Skip to content

CrowdStrike

US · CRWD #70 by market cap Listed 2019 Quant Rating C 58
213.10 -1.87 -0.87%
Collector offline (last heartbeat: 19123s ago) · 2026-09-04 20:02
Pre-market 212.07 -1.35%
After-hours 213.20 +0.05%
Overnight 215.11 +0.07%
Market cap
218.20B
P/E (TTM)
5,607.89
P/B
42.77
EPS
-0.16

Valuation each multiple against its own 5-year range

P/B ratio 42.74 Expensive vs history 86th percentile
5-year average 32.87 · #146 of 152 in Software - Infrastructure
P/E ratio 5,603.00 Expensive vs history 100th percentile
5-year average -845.05 · forward 1,159.23 · #83 of 83 in Software - Infrastructure
P/S ratio 40.40 Expensive vs history 93rd percentile
5-year average 25.43 · forward 32.81 · #150 of 172 in Software - Infrastructure

Vs. peers Software - Infrastructure

Company Market cap P/E (TTM) P/B Div yield
CrowdStrike (CRWD) 218.20B 5,607.89 42.77 0.00%
Microsoft (MSFT) 3.71T 27.84 8.39 0.71%
Oracle (ORCL) 457.36B 27.23 12.18 1.26%
Palantir (PLTR) 418.93B 149.00 42.86 0.00%
Palo Alto Networks (PANW) 271.61B 833.15 9.88 0.00%

Other StockVane-tracked companies in the same industry.

Morningstar

★★☆☆☆ Fair value152.00 Economic moatWide UncertaintyVery High Capital allocationExemplary

Trading 28.7% above Morningstar's fair value estimate.

Analyst note

CrowdStrike closed out its second quarter of fiscal 2027 with sales growing 26% to $1.47 billion and adjusted operating margins expanding 350 basis points to 25.3%. The firm added a record $333 million in net new annual recurring revenue, or ARR, up 51%.

Why it matters: CrowdStrike's business is firing on all cylinders, with the firm's ARR expanding 25% to $5.84 billion. Beyond its core endpoint solution, cloud, identity, and security operations grew a combined 39% and now contribute 37% of total ARR. This top-line reacceleration is driven by increased spending on cyber solutions as enterprises beef up defenses against increasingly capable AI-driven cyber attacks. In this arms race-type scenario, cyber vendors are seeing clear business wins. Enterprise buying momentum can be gauged by forward-looking metrics such as remaining performance obligations, or RPO, which grew 49%, highlighting the large deals the firm is signing as customers consolidate cyber spending on CrowdStrike's platform.

The bottom line: We raise our fair value estimate for wide-moat CrowdStrike to $152, up from $133. Shares traded up more than 10% after hours. While we continue to view them as overvalued in our base case, we also model a separate bull case for CrowdStrike, which results in a fair value of $230. Our bull case incorporates a material acceleration in fiscal 2028 and strong growth after that, driven largely by AI-induced cyber demand. At current levels, CrowdStrike's enterprise value is roughly 35 times fiscal 2027's expected sales, far above the median 10 times sales for our broader cyber coverage. Put another way, the stock is priced for perfection.

Key stats: Ending ARR from customers that have adopted CrowdStrike's Flex program more than doubled to $2.3 billion. We see this trend as a clear vote of confidence in the firm's platform consolidation strategy.

Fair value

Our fair value estimate for CrowdStrike is $152 per share, implying a fiscal 2027 enterprise value/sales multiple of 24 times and a fiscal 2028 EV/sales of 19 times.

We forecast CrowdStrike's revenue growing at a 23% compound annual growth rate over the next five years. We expect the firm to continually expand its client base while maintaining strong upselling performance among existing clients, as evidenced by its stellar multi-module adoption rates. In our view, endpoint security remains a key area of enterprise security spend, and we expect it to remain important for clients in the coming years.

CrowdStrike's "land-and-expand" model has shown consistent success, with the firm able to reliably expand sales from existing customers by selling them additional modules, including security operations, cloud, identity, and, more recently, AI-native security tooling, or by protecting more endpoints per customer. We expect this upselling velocity to persist as the ever-changing threat landscape, now intensified by adversaries leveraging AI, provides strong momentum for CrowdStrike's sales, and the firm continues to consolidate more security spending on its Falcon platform.

CrowdStrike's gross margins have expanded into the mid-70s range in recent periods. As the company continues to grow and software becomes a larger part of its top line, we expect further gross margin expansion. We see this phenomenon across our coverage as software firms spread their costs over an increasing revenue base, reducing the cost of sales as a fraction of sales. As a result, we are modeling GAAP gross margins to expand to around 80% over our 10-year explicit forecast.

CrowdStrike has spent heavily on research and sales in the past. However, as the company scales, we expect these line items to decrease as a percentage of sales. Having largely recovered from the margin pressure caused by the July 2024 outage, we expect the firm to reach GAAP profitability in fiscal 2027 and proceed to materially expand its margin profile as it seeks to balance growth with profitability. We continue to expect CrowdStrike's cash flow generation profile to remain strong, with free cash flow margins expanding beyond the 40% range over our explicit forecast period.

Economic moat

We believe CrowdStrike merits a wide-moat rating owing to strong customer switching costs associated with Falcon, its cybersecurity platform. We view endpoint security as a vital component of any modern enterprise's IT security infrastructure and, according to our estimates, accounts for roughly a fifth of overall cybersecurity spending. Within the endpoint security space, CrowdStrike has cemented its position as a clear market leader. Additionally, we believe that the value of CrowdStrike's platform can be gleaned from the firm's impressive net retention metrics and strong customer growth. We also believe that CrowdStrike, like other endpoint security vendors, stands to benefit from secular tailwinds as enterprises continue to spend heavily on endpoint security. With increased adoption of endpoint security platforms, as enterprises migrate away from legacy antiviruses, and a sticky platform ensuring that the firm can land and expand its customers, we believe CrowdStrike is more than likely to generate excess returns over the next 20 years .

The primary market in which CrowdStrike competes is endpoint detection and response, or EDR. EDR's primary focus is on monitoring an enterprise's endpoints for nefarious cyberactivity. The evolution of EDR has also been aided by the structural change in how enterprises define their security perimeters. Historically, there has been a relatively contained picture of an enterprise's security infrastructure, think of a house with endpoint protection available at every entry point. However, this way of managing security is rapidly becoming obsolete. As more companies undergo digital transformations, the updated form of protection focuses on securing an enterprise from various attack vectors that did not previously exist, such as IoT instances and cloud workloads. Moreover, the complexity of the threat landscape continues to grow, with adversaries increasingly leveraging AI to accelerate and sophisticate attacks, further adding to the value that EDR vendors such as CrowdStrike provide to their customers.

CrowdStrike's primary product is its Falcon platform. The cloud-native solution consists of more than 30 modules with services ranging from threat intelligence, hunting, mitigation, and response. The attack surface that Falcon covers also extends well beyond endpoints, with the platform spanning cloud workloads, identity protection, and posture management among other modules. With pricing determined on a per-agent basis, Falcon allows clients to quickly scale up demand as their business grows, allowing CrowdStrike to maintain solid upselling velocity. Other than securing an enterprise's infrastructure, we believe Falcon can also improve labor productivity. By hunting, tracking, and neutralizing cyberthreats, CrowdStrike's platform enables IT security teams to free themselves of taxing threat detection and focus more on bigger-picture IT security issues.

In our view, the firm's entrenchment in its clients' IT security ecosystems creates high switching costs. We believe enterprises exhibit loss aversion when it comes to IT security, as there is an operational risk when switching EDR vendors, including loss of analytics during the changeover, project execution risk, and operational disruption. The more critical the function and the more touchpoints across an organization a vendor has, the higher the switching costs. We believe that any security-related data loss, disruption, or lapse is a material cost associated with switching vendors. We also do not think that enterprises nickel and dime their way to picking an EDR vendor. Typically, companies will select a vendor based on performance rather than price, provided that it has the features most relevant to them.

Customers that adopt security solutions do so to take uncertainty off the table, and switching vendors often brings that uncertainty back into play. CrowdStrike's gross retention has remained well above 95%, implying a customer lifetime of more than 20 years. At the same time, by upselling its customers into buying more Falcon modules and expanding agent deployment, CrowdStrike has maintained a net retention rate of more than 110%. We expect increased customer stickiness as the firm continues to expand its client base and set of solutions.

Along with high switching costs, we believe a network effect reinforces CrowdStrike's economic moat. Cybersecurity, in its essence, is a data problem, and attacks are now too overwhelming to be handled manually. In turn, vendors have developed AI solutions to automate processes and detect threats, especially novel zero-day attacks. However, AI and machine learning solutions are only as good as the data fed to them. This need for high-quality data is where we see entrenched platform vendors such as CrowdStrike having a distinct edge. For some context, CrowdStrike's AI-powered platform processes trillions of signals a day, giving it vast amounts of data to improve its own offerings and enhance its value proposition to new customers.

By collecting and analyzing this rich data flowing into its platform, CrowdStrike can uncover threats and new threat signatures that are then used to update its entire client base's security posture. This network effect is at CrowdStrike's core, with even the firm's name being a nod to its ability to collate massive amounts of security data to thwart nefarious activity across its client base. As more data comes in, the Falcon platform becomes better at detecting and mitigating cyberthreats. As a result, more customers onboard CrowdStrike due to its superior capabilities, which in turn leads to more data, and the flywheel spins faster. We see this network effect as reinforcing switching costs as well, with customers hesitant to leave CrowdStrike as doing so may entail losing access to its crowd-based threat intelligence capabilities.

Bull case

CrowdStrike has strong secular tailwinds given that the endpoint, cloud, identity, and security operations markets are projected to grow rapidly

CrowdStrike has market leadership in endpoint security and has high enterprise penetration within the space.

The company stands to benefit as clients consolidate vendors and opt for a platform-based cybersecurity approach.

Bear case

Large public cloud vendors often offer their own cybersecurity solutions, which could hamper CrowdStrike’s growth opportunities.

CrowdStrike faces competition from vendors like Palo Alto that have increasingly made investments in the endpoint security space.

There always remains a risk that CrowdStrike may miss out on the next big technology, thereby allowing its competitors to catch up.

Quote time 2026-09-04 20:02:23

For reference only, not investment advice.