TL; DR
The growth transition is finally becoming visible: organic net-new ARR grew 17%, non-seat products exceeded 100% ARR growth, Zero Trust Everywhere reached 950+ enterprises, and Z-Flex TCV surged above $770 million.
The thesis has become more precise: Zscaler does not need to become the “brain” of AI security. Identity, endpoint and other systems can make decisions upstream; Zscaler can still become increasingly valuable as the privileged place where those decisions are enforced.
The new uncertainty is economic: machine traffic expands the number of interactions Zscaler can secure, but transactions have risen above 750 billion per day while FCF margins have weakened and CapEx is rising. The question is whether this is temporary equipment spending or structurally greater capital intensity.
“I was right that Zscaler’s inline architecture is valuable. I was too quick to assume it would become the highest-value control plane in the AI era.”
That was where I left Zscaler three months ago. Q3 had not broken the business: revenue and ARR were still growing 25%, Z-Flex was expanding, non-seat usage was scaling, and margins had reached a record. What broke was the inference I had been drawing from those facts. A valuable architecture did not necessarily mean Zscaler would own the most valuable security decision in an AI world; intelligence could increasingly move upstream toward identity, endpoint, code, browser and agent governance while Zscaler remained indispensable plumbing.
Q4 should be judged against that correction, not used to erase it.
On that basis the quarter delivered something much more useful than another beat: a split verdict. The growth transition we had been waiting for became considerably more tangible. Organic net-new ARR accelerated, non-seat products kept taking share of new business, Z-Flex took another extraordinary step higher, Zero Trust Everywhere adoption jumped, and the sales disruption that haunted Q3 largely disappeared from the numbers.
The cash-flow test, though, did not pass. And management’s FY27 guide still assumes remarkably little of Q4’s acceleration survives.
The first finding makes me more constructive. The second prevents the old bull case from simply returning.
What Did Not Change
Across this series I have used several analogies to describe Zscaler: Salesforce, ServiceNow, and most recently the cardiovascular system. The changing metaphors reflected a real evolution in the thesis, but they also risked making the underlying view appear less stable than it was. The architecture thesis has barely changed. What changed was how much economic dominance I was willing to infer from it.
Zscaler’s original insight was that the corporate network was the wrong thing to trust. Instead of putting a user onto that network and then protecting everything behind it, the Zero Trust Exchange connects a specific entity to a specific application according to policy. The architecture governs an interaction rather than protects a location.
That becomes more relevant as the entity changes from an employee to a workload, branch, device, model or autonomous agent. Zscaler’s 10-K now explicitly describes the Exchange as connecting users, devices, workloads and AI agents to applications, models and data according to identity and business policy.
Q3’s correction was that circulation is not cognition. The cardiovascular system can be essential without being the brain. If the highest-value security decision increasingly occurred in identity, endpoint or code before traffic ever reached Zscaler, then the Exchange could remain extremely durable without becoming the control point I had once assumed.
The burden of proof therefore became economic. Zscaler had to demonstrate that workloads, branches, data, agents and the products surrounding them could become large enough to alter company-level growth before the original user-security business matured.
Q4 began to do exactly that.
The Transition Appears in the Numbers
The headline quarter was excellent. Revenue reached $898 million, ARR $3.77 billion, net-new ARR $246 million and non-GAAP operating margin a record 24.3%. The $246 million net-new ARR result also just cleared the roughly $245 million investor bar we had identified before earnings.
But those are not the figures that change the thesis. These are:
Excluding Red Canary, net-new ARR was $232 million and grew 17%, after growing 7% in FY25 and 10% in the first half of FY26. Zero Trust Everywhere enterprises have moved from more than 350 at FY25-end to more than 700 in Q3 and more than 950 in Q4.
Z-Flex supplies the commercial connection. Q4 TCV exceeded $770 million, up more than 60% sequentially, while FY26 Z-Flex customers increased ARR by nearly 30% on average.
I used to describe this as lock-in; that was too strong. Z-Flex is better understood as commercial pre-commitment. Once a customer has committed a multi-year budget, adding another Zscaler capability no longer requires starting procurement from scratch. The next product is easier to adopt than the first.
That creates what I think is Zscaler’s more defensible economic advantage: economies of scope around an enforcement point. More of a customer’s estate comes under common policy; each additional use case increases the usefulness of consistent enforcement; Z-Flex reduces the friction required to expand that footprint.
This is why the 30% non-seat figure matters more to me than the revenue beat. An employee-seat business grows with headcount. A security system priced around workloads, branches, data volumes and machine activity can grow with the number of interactions being secured.
AI matters because it radically increases those interactions.
Upstream Was Too Binary
Jay Chaudhry made the distinction unusually clearly:
“While identity solutions answer ‘who’ is requesting access, our in-line platform determines ‘what’ that user or agent should be allowed to do.”
Q3 framed the emerging security world as anticipation versus interception. That now looks too binary.
Symmetry’s Access Graph maps relationships among entities, applications and data. Data Security and Security for AI add context about sensitive information, models, prompts and permissions. The Zero Trust Exchange applies policy to the actual interaction. Agentic SecOps, combining Zscaler telemetry with Red Canary’s operating expertise, is intended to investigate and remediate after something happens.
The ambition increasingly looks like:
understand → decide → enforce → observe → remediate.
That does not mean Zscaler suddenly becomes the brain. Microsoft begins with identity, endpoint and distribution; CrowdStrike with endpoint telemetry and response; Palo Alto with network-security incumbency and consolidation. Each has a legitimate claim on an important part of the decision chain.
Zscaler’s more interesting proposition is that intelligence gathered elsewhere becomes more useful when attached to an unusually powerful place to turn that intelligence into action.
In other words, Zscaler may not need to own every upstream security decision. It needs to remain the privileged place where those decisions are enforced.
Q4 makes that possibility materially more credible.
The Bill We Do Not Yet Understand
There is, however, a potentially uncomfortable consequence to the same transition.
As Zscaler secures more workloads, branches and machine interactions, the Exchange itself must carry more traffic and make more real-time decisions. Zscaler now processes more than 750 billion transactions per day, compared with roughly 500 billion in earlier periods.
At the same time, the cash-flow economics have weakened. FY26 FCF margin fell to 23%, and FY27 guidance remains only 23–23.5%. CapEx is expected to reach the low teens as a percentage of revenue.
It is tempting to make those facts one elegant story: machine traffic expands, Zscaler needs more equipment to inspect it, and the new growth model is inherently more capital intensive.
Q4 does not prove that.
Management attributes much of the increase to higher memory, storage and processor prices, tighter availability, and purchases that were accelerated when equipment became available. There are therefore at least three things inside current CapEx: component inflation, purchasing timing, and potentially a structurally larger equipment requirement as non-human traffic grows.
The distinction matters enormously.
Our old bull case effectively wanted the revenue opportunity of traffic-based security with the capital intensity of seat-based SaaS. That may have been too generous. But assuming FY27’s unusual equipment spend is the permanent economics of the business would be equally premature.
This is now a second fundamental question alongside growth: what does machine-scale enforcement cost once component prices and purchase timing normalize?
We do not know yet.
The Model Still Does Not Believe the Quarter
There is an even cleaner contradiction.
FY27 ARR guidance is $4.396–4.426 billion. At the midpoint, subtracting Q4’s $3.771 billion ending ARR implies about $640 million of FY27 net-new ARR. Organic FY26 ARR increased by roughly $615 million.
In other words, management’s FY27 guide implies only about:
4% growth in annual net-new ARR.
Q4 organic net-new ARR grew 17%.
Oppenheimer challenged Kevin Rubin on exactly this calculation. Rubin did not dispute it. He instead pointed to the sales-leadership transition, the ramp of Agentic SecOps, stable 115% NRR, investment in new-logo coverage and AI tailwinds. He also said Zscaler had not specifically called out the contribution from Security for AI in guidance.
Both numbers cannot describe the normalized future.
Either Q4 was an unusually strong fiscal-year-end quarter and the FY27 model is approximately right, or management has built considerably more conservatism into the annual guide than current demand warrants.
That is also why Zscaler has not yet recovered like several cybersecurity peers after the AI scare. The argument that AI itself disrupts Zscaler looks increasingly weak. What remains unresolved is whether Zscaler’s strategic relevance translates into faster financial growth.
CrowdStrike and Palo Alto have already persuaded growth investors of that connection. Zscaler has connected its story to leading indicators while still formally guiding like a 16–17% company.
The market is entitled to wait.
There are disclosure reasons to wait too. Security for AI bookings increased more than 50% sequentially and pipeline 75%, but management still does not provide a clean Security for AI ARR figure. Z-Flex TCV is spectacular, but longer contracts are not the same as recurring-revenue acceleration. RPO growth has fallen from 35% in Q1 to 27% in Q4, only modestly ahead of revenue, meaning our old “speedometer versus engine” argument has lost much of its informational advantage.
The mechanism increasingly looks real. The model still assumes it barely matters. One of them must move.
Three Prices, Three Zscalers
For a company at this stage, I would value the scenarios primarily on EV/revenue, with growth, operating margin and FCF margin determining what multiple is deserved. FCF is an important quality check; it should not be allowed to answer an unresolved capital-intensity question by itself.
Our estimates. Price ranges use FY29 revenue implied by the stated CAGR, approximately 180 million diluted shares and current net cash as a conservative capital-structure assumption.
The bear case does not require Zscaler to lose relevance. The user-security core simply matures faster than non-seat security can compensate, while higher capital intensity prevents a premium valuation.
The base case is more interesting because it requires no return to hypergrowth. Zscaler compounds revenue around 17–18%, improves FCF toward the mid-20s, and proves that workloads, branches, data and agents can sustain the business as seat growth matures. Once the Q3 uncertainty has been resolved favorably, I think a 7.5–8.0x terminal revenue multiple is reasonable; a business still growing high-teens with mid-20s cash margins would deserve more than the valuation of a permanently decelerating SASE vendor.
The bull case requires actual company-level reacceleration. Security for AI and Agentic SecOps need to become meaningful recurring businesses, non-seat adoption needs to move materially beyond 30%, and the incremental equipment burden has to prove scalable enough for FCF margins to approach the high-20s.
Using midpoint outcomes gives a probability-weighted three-year value around $245, versus roughly $178 today. The important change from Q3 is not that the bull case deserves to be inflated again. It is that Q4 makes the pure maturity case less likely.
That is a healthier reason for fair value to rise.
The Trial Continues
The variant perception has narrowed considerably over the last year. It is no longer “the market sees software; we see security infrastructure.” That was too easy.
The market now sees a strategically relevant company whose growth is settling around 16–17% and whose cash economics may be becoming somewhat more capital intensive. Management wants investors to see a deliberately cautious guide sitting on top of accelerating organic net-new ARR, record sales productivity, rapidly growing non-seat security and AI products that are still early.
I think the market is right to withhold the old premium multiple. I also think it is increasingly difficult to look at 17% organic net-new ARR growth, >100% non-seat ARR growth, 950+ Zero Trust Everywhere enterprises and $770 million of Z-Flex TCV and conclude that nothing underneath the headline growth rate is changing.
Q3 correctly raised the burden of proof. Q4 has begun to meet it.
The remaining tests are clearer now. Organic net-new ARR needs to stay in the mid-teens rather than collapse back toward the ~4% annual growth embedded in guidance. Non-seat contribution needs to move toward 35%. Z-Flex must convert commitment into ARR. Security for AI needs to graduate from bookings and pipeline to recurring revenue. Agentic SecOps needs to become financially visible in the second half.
And the newest test may be the most important one we were not asking three months ago: whether FY27’s elevated equipment spending normalizes as prices and purchase timing normalize, or whether carrying machine-scale traffic really does require more capital than our old model assumed.
The architectural thesis did not change. Q3 changed what I was willing to infer from it. Q4 changes the evidence.
The transition is increasingly visible in the operating data. What we still do not know is the normalized cost of running it.
That is what FY27 now must answer.
Disclaimer:
The content does not constitute any kind of investment or financial advice. Kindly reach out to your advisor for any investment-related advice. Please refer to the tab “Legal | Disclaimer” to read the complete disclaimer.










