Qualys
Annual Report 2018

Plain-text annual report

Table of ContentsUNITED STATESSECURITIES AND EXCHANGE COMMISSIONWashington, D.C. 20549__________________FORM 10-K__________________xAnnual Report Pursuant to Section 13 or 15(d) of the Securities Exchange Act of 1934For the Annual Period Ended December 31, 2018oroTransition Report Pursuant to Section 13 or 15(d) of the Securities Exchange Act of 1934For the transition period from toCommission file number 001-35662__________________QUALYS, INC.(Exact name of registrant as specified in its charter)__________________Delaware 77-0534145(State or other jurisdiction of (I.R.S. Employerincorporation or organization) Identification Number)919 E. Hillsdale Boulevard, 4th Floor, Foster City, California 94404(Address of principal executive offices, including zip code)(650) 801-6100(Registrant’s telephone number, including area code)__________________Securities registered pursuant to section 12(b) of the Act:Title of each class Name of each exchange on which registeredCommon stock, $0.001 par value per share NASDAQ Stock MarketSecurities registered pursuant to section 12(g) of the Act: NoneIndicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes x No oIndicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes o No xIndicate by check mark whether the Registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934during the preceding 12 months (or for such shorter period that the Registrant was required to file such reports), and (2) has been subject to such filingrequirements for the past 90 days. Yes x No oIndicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 ofRegulation S-T during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes x No oIndicate by check mark if disclosure of delinquent filers pursuant to Item 405 of Regulation S-K(§229.405 of this chapter) is not contained herein, and will notbe contained, to the best of registrant's knowledge, in definitive proxy or information statements incorporated by reference in Part III of this Form 10-K or anyamendment to this Form 10-K. oIndicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company or anemerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company” and “emerging growth company” inRule 12b-2 of the Exchange Act. (Check one):Large accelerated filerx Accelerated filero Non-accelerated filero Smaller reporting companyo Emerging growth companyoIf an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new orrevised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. oIndicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Exchange Act). Yes o No xAs of June 30, 2018, the aggregate market value of voting shares of common stock held by non-affiliates of the registrant was $2,395 million based on the lastreported sale price of the registrant's common stock on June 30, 2018. Shares of common stock held by each executive officer and director and by eachperson who owns 10% or more of the outstanding common stock have been excluded in that such persons may be deemed to be affiliates. Thisdetermination of affiliate status is not necessarily a conclusive determination for other purposes. The number of shares of the Registrant's common stock outstanding as of January 31, 2019 was 39,038,263 shares.DOCUMENTS INCORPORATED BY REFERENCEPortions of the registrant's Proxy Statement for its 2019 Annual Meeting of Stockholders are incorporated by reference in Part III of this Annual Report on Form10-K where indicated. Such proxy statement will be filed with the Securities and Exchange Commission within 120 days of the registrant's fiscal year endedDecember 31, 2018. Table of ContentsQualys, Inc.TABLE OF CONTENTS PagePART IItem 1.Business4Item 1A.Risk Factors15Item 1B.Unresolved Staff Comments36Item 2.Properties38Item 3.Legal Proceedings38Item 4.Mine Safety Disclosures38PART IIItem 5.Market for Registrant's Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities39Item 6.Selected Consolidated Financial Data42Item 7.Management's Discussion and Analysis of Financial Condition and Results of Operations43Item 7A.Quantitative and Qualitative Disclosures About Market Risk59Item 8.Financial Statements and Supplementary Data60Item 9.Changes in and Disagreements with Accountants on Accounting and Financial Disclosure95Item 9A.Controls and Procedures95Item 9B.Other Information96PART IIIItem 10.Directors, Executive Officers and Corporate Governance96Item 11.Executive Compensation96Item 12.Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters96Item 13.Certain Relationships and Related Transactions, and Director Independence96Item 14.Principal Accounting Fees and Services96PART IVItem 15.Exhibits and Financial Statement Schedules98SignaturesX 2 Table of ContentsPART IForward-Looking StatementsIn addition to historical information, this Annual Report on Form 10-K contains "forward-looking" statements within the meaning of the federalsecurities laws, which statements involve substantial risks and uncertainties. Forward-looking statements generally relate to future events or ourfuture financial or operating performance. In some cases, it is possible to identify forward-looking statements because they contain words such as"anticipates," "believes," "contemplates," "continue," "could," "estimates," "expects," "future," "intends," "likely," "may," "plans," "potential,""predicts," "projects," "seek," "should," "target," or "will," or the negative of these words or other similar terms or expressions that concern ourexpectations, strategy, plans or intentions. Forward-looking statements contained in this Annual Report on 10-K include, but are not limited to,statements about:•our financial performance, including our revenues, costs, expenditures, growth rates, operating expenses and ability to generatepositive cash flow to fund our operations and sustain profitability;•anticipated technology trends, such as the use of cloud solutions;•our ability to adapt to changing market conditions;•economic and financial conditions, including volatility in foreign exchange rates;•our ability to diversify our sources of revenues, including selling additional solutions to our existing customers and our ability topursue new customers;•the effects of increased competition in our market;•our ability to innovate, enhance our cloud solutions and platform and introduce new solutions;•our ability to effectively manage our growth;•our anticipated investments in sales and marketing, our infrastructure, new solutions, research and development, and acquisitions;•maintaining and expanding our relationships with channel partners;•our ability to maintain, protect and enhance our brand and intellectual property;•costs associated with defending intellectual property infringement and other claims;•our ability to attract and retain qualified employees and key personnel, including sales and marketing personnel;•our ability to successfully enter new markets and manage our international expansion;•our expectations, assumptions and conclusions related to our provision for income taxes, our deferred tax assets and our effectivetax rate; and•other factors discussed in this Annual Report on Form 10-K in the sections titled "Risk Factors," "Management's Discussion andAnalysis of Financial Condition and Results of Operations" and "Business."We have based the forward-looking statements contained in this Annual Report on Form 10-K primarily on our current expectations andprojections about future events and trends that we believe may affect our business, financial condition, results of operations and prospects. Theresults, events and circumstances reflected in these forward-looking statements are subject to risks, uncertainties, assumptions, and other factorsincluding those described in Part I, Item 1A (Risk Factors) of this Annual Report. Moreover, we operate in a very competitive and rapidly changingenvironment. New risks and uncertainties emerge from time to time, and it is not possible for us to predict all risks and uncertainties that couldhave an impact on the forward-looking statements used herein. We cannot provide assurance that the results, events, and circumstances reflectedin the forward-looking statements will be achieved or occur, and actual results, events or circumstances could differ materially from thosedescribed in the forward-looking statements.You should not rely on forward-looking statements as predictions of future events. Except as required by law, neither we nor any other personassumes responsibility for the accuracy and completeness of the forward-looking statements, and we undertake no obligation to update anyforward-looking statements to reflect events or circumstances after the date of such statements.Qualys, the Qualys logo and other trademarks and service marks of Qualys appearing in this Annual Report on Form 10-K are the property ofQualys. This Annual Report on Form 10-K also contains trademarks and trade names of other businesses that are the property of their respectiveholders. We have omitted the ® and ™ designations, as applicable, for the trademarks used in this Annual Report on Form 10-K.3 Table of ContentsItem 1.BusinessOverviewWe are a pioneer and leading provider of a cloud-based platform delivering security and compliance solutions that enable organizations toidentify security risks to their information technology (IT) infrastructures, help protect their IT systems and applications from ever-evolving cyber-attacks and achieve compliance with internal policies and external regulations. Our cloud solutions address the growing security and compliancecomplexities and risks that are amplified by the dissolving boundaries between internal and external IT infrastructures and web environments, therapid adoption of cloud computing, containers and serverless IT models, and the proliferation of geographically dispersed IT assets. Our integratedsuite of security and compliance solutions delivered on our Qualys cloud platform (Qualys Cloud Platform) enables our customers to identify andmanage their IT assets, collect and analyze large amounts of IT security data, discover and prioritize vulnerabilities, recommend remediationactions and verify the implementation of such actions. Organizations use our integrated suite of solutions delivered on our Qualys Cloud Platformto cost-effectively obtain a unified view of their IT asset inventory as well as security and compliance posture across globally-distributed ITinfrastructures as our solution offers a single platform for information technology, information security, application security, endpoint, developersecurity and cloud teams.IT infrastructures are more complex and globally-distributed today than ever before, as organizations of all sizes increasingly rely upon amyriad of interconnected information systems and related IT assets, such as servers, databases, web applications, routers, switches, desktops,laptops, other physical and virtual infrastructure, and numerous external networks and cloud services. In this environment, new and evolving digitaltechnologies intended to improve organizations’ operations can also increase vulnerability to cyber-attacks, which can expose sensitive data,damage IT and physical infrastructures, and result in serious financial or reputational consequences. In addition, the rapidly increasing amount ofdata and devices in IT environments makes it more difficult to identify and remediate vulnerabilities in a timely manner. The predominant approachto IT security has been to implement multiple disparate security products that can be costly and difficult to deploy, integrate and manage and maynot adequately protect organizations. As a result, we believe there is a large and growing opportunity for comprehensive cloud-based IT securityand compliance solutions delivered in a single platform.We designed our Qualys Cloud Platform to transform the way organizations secure and protect their IT infrastructures and applications. Ourcloud platform offers an integrated suite of solutions that automates the lifecycle of asset discovery and management, security assessments, andcompliance management for an organization’s IT infrastructure and assets, whether such infrastructure and assets reside inside the organization,on their network perimeter, on endpoints or in the cloud. Since inception, our solutions have been designed to be delivered through the cloud and tobe easily and rapidly deployed on a global scale, enabling faster implementation and lower total cost of ownership than traditional on-premisesenterprise software products. Our customers, ranging from some of the largest global organizations to small businesses, are served from ourglobally-distributed cloud platform, enabling us to rapidly deliver new solutions, enhancements and security updates.We believe that our cloud platform provides our customers with unique advantages, including:•No hardware to buy or manage. There is no infrastructure or software to buy and maintain thus reducing our customers’ operatingcosts; all services are accessible in the cloud via web interface. Qualys operates and maintains the platform.•Real-time visibility in one place, anytime and anywhere. Our customers can conveniently see their security and compliance postureacross their global IT asset inventory in one browser window, without plugins or a virtual private network (VPN), whenever andwherever Internet access is available.•Easy global scanning. Our customers can easily perform scans on geographically distributed and segmented networks at theperimeter, behind the firewall, on dynamic cloud environments and on endpoints.•Seamless scaling. Our cloud platform is a scalable, comprehensive, and end-to-end solution for the IT security needs of ourcustomers. Our customers can seamlessly add new coverage, users and services after they have deployed our platform.4 Table of Contents•Up to date resources. Qualys has one of the largest knowledge bases of vulnerability signatures in the industry. All security updatesare made in real-time.•Data stored securely. Data is securely stored and processed in a multi-tiered architecture of load-balanced servers. Our encrypteddatabases are physically and logically secured.We were founded and incorporated in December 1999 with a vision of transforming the way organizations secure and protect their ITinfrastructure and applications and initially launched our first cloud solution, Vulnerability Management (VM), in 2000. As VM gained acceptance,we introduced additional solutions to help customers manage increasing IT security and compliance requirements. Today, the suite of solutionsthat we offer on our cloud platform and refer to as the Qualys Cloud Apps helps our customers protect a range of on-premise assets, endpointsand cloud environments. These solutions and their Cloud Apps address and include:•IT Security: Vulnerability Management (VM), Threat Protection (TP), Continuous Monitoring(CM), indication of Compromise (IOC), Certificate Assessment (CRA);•Compliance Monitoring: Policy Compliance (PC), PCI Compliance (PCI), File IntegrityMonitoring (FIM), Security Configuration Assessment (SCA), Security Assessment Questionnaire (SAQ);•Web Application Security: Web Application Scanning (WAS), Web Application Firewall (WAF);•Global IT Asset Management: Asset Inventory (AI), CMDB Sync (SYN), Certificate Inventory (CRI); and•Cloud/Container Security: Cloud Inventory (CI), Cloud Security Assessment (CSA), Container Security(CS).We provide our solutions through a software-as-a-service model, primarily with renewable annual subscriptions. These subscriptions requirecustomers to pay a fee in order to access each of our cloud solutions. We generally invoice our customers for the entire subscription amount atthe start of the subscription term, and the invoiced amounts are treated as deferred revenues and are recognized ratably over the term of eachsubscription. We continue to experience significant revenue growth from our existing customers as they renew and purchase additionalsubscriptions.Our Qualys Cloud Platform is currently used by over 12,200 customers and active users in more than 130 countries, including a majority ofeach of the Forbes Global 100 and Fortune 100. Our revenues increased to $278.9 million in 2018 from $230.8 million in 2017 and $197.9 million in2016. Our VM solutions (including VM, CM, TP, Cloud Agent for VM, allocated scanner revenue and Qualys Private Cloud Platform) have provideda majority of our revenues to date, representing 74%, 74% and 76% of total revenues in 2018, 2017 and 2016, respectively. We generated netincome of $57.3 million in 2018, $40.4 million in 2017 and $19.2 million in 2016. Total assets as of December 31, 2018 and 2017 were $585.7million and $537.5 million, respectively. Our PlatformOur cloud platform consists of a suite of IT security, compliance monitoring, web application security, IT asset management and cloud andcontainer security solutions, which we refer to as the Qualys Cloud Apps, that leverages our shared and extensible core services and our highlyscalable multi-tenant cloud infrastructure. We also provide open application program interfaces, or APIs, and other developer tools that allow thirdparties to embed our technology into their solutions and build applications on our cloud platform.Our cloud platform utilizes physical and virtual sensors, and cloud agents that provide our customers with continuous visibility enablingcustomers to respond to threats immediately.The Qualys Cloud Platform automatically gathers and analyzes security and compliance data in a scalable, state-of-the-art backend. Thetechnology underlying our cloud infrastructure enables us to ingest, process, analyze and store a high volume of sensor data coming from ouragents, scanners and passive analyzers, and correlate information at very high speeds in a distributed manner for millions of devices.5 Table of Contents6 Table of ContentsOur cloud platform is delivered to our customers via our shared platform offering from our global data centers, or via our private platformoffering, Qualys Private Cloud Platform (PCP), for customers or partners that want the platform to reside within the customer's data center. ThePCP is a standalone version of our multi-layer, multi-tenant services architecture and is a fully integrated turnkey solution, making it morescalable, cost effective and faster to deploy within a customer's data center. Solutions delivered through our PCP are typically on the samesubscription basis as solutions delivered through our shared platform. Our PCP utilizes hardware and software owned by us and is physicallylocated on the customer's premises. The customer is not permitted to take possession of the software or access the software code. We also offerour PCP as a subscription-based platform services to the customer using a virtual version of our software. This virtualized PCP allows us toextend our security and compliance solutions without the complexity and cost associated with deploying traditional enterprise software.Additionally, in 2016, we introduced the Private Cloud Platform Appliance (PCPA), an on-premises security and compliance solution packaged in aform-factor for medium-sized companies.Qualys Core ServicesOur core services enable integrated workflows, management and real-time analysis and reporting across all of our IT security and compliancesolutions for our customers inside their organizations, on the perimeter, on endpoints or in the cloud.Our core services constitute dynamic and customizable dashboards and centrally managed, self-updating integrated Cloud Apps, throughwhat we call a “single-pane-of-glass” user interface. Our interactive, dynamic dashboards and cloud platform allow our customers to aggregate andcorrelate all of their IT, security and compliance data in one place, drill down into details, and generate reports customized for different audiences.Our cloud platform’s powerful elasticsearch clusters enable customers to instantly find detailed data on any asset.Our core services include:•Asset Tagging and Management. Enables customers to easily identify, categorize and manage large numbers of assets in highly dynamicIT environments and automates the process of inventory management and hierarchical organization of IT assets. Built on top of this coreservice is the Qualys AI framework, which is a global asset inventory service enabling our customers to search for information on any ITasset, scaling to millions of assets for customers of all sizes, helping IT and security personnel to search IT assets and maintain an up-to-date inventory on a continuous basis.•Reporting and Dashboards. A highly configurable reporting engine that provides customers with reports and dashboards based on theirroles and access privileges.•Questionnaires and Collaboration. A configurable workflow engine that enables customers to easily build questionnaires and captureexisting business processes and workflows to evaluate controls and gather evidence to validate and document compliance.•Remediation and Workflow. An integrated workflow engine that allows customers to automatically generate helpdesk tickets forremediation and to manage compliance exceptions based on customer-defined policies, enabling subsequent review, commentary,tracking and escalation. This engine automatically distributes remediation tasks to IT administrators upon scan completion, tracksremediation progress and closes open tickets once patches are applied and remediation is verified in subsequent scans.•Big Data Correlation and Analytics Engine. Provides elasticsearch capabilities for indexing, searching and correlating large amounts ofsecurity and compliance data with other security incidents and third-party security intelligence data. Embedded workflows enablecustomers to quickly assess risk and access information for remediation, incident analysis and forensic investigations.•Alerts and Notifications. Creates email notifications to alert customers of new vulnerabilities, malware infections, scan completion, opentrouble tickets and system updates.7 Table of ContentsQualys Cloud AppsMany organizations have an array of heterogeneous point tools that do not interoperate well and are difficult and costly to maintain andintegrate, making it difficult for Chief Information Officers (CIOs) and Chief Information Security Officers (CISOs) to obtain a single, unified view oftheir organization’s security and compliance posture. The Qualys Cloud Platform and its Cloud Apps help organizations escape this tool-fragmentation dilemma by drastically simplifying their security stacks and regaining unimpeded visibility across their IT environment.The Cloud Apps are self-updating, centrally managed and tightly integrated, and cover a broad range of functionality in areas such as ITsecurity, compliance monitoring, web application security, IT asset management and cloud and container security solutions.From inception through December 31, 2017, we have added the following Cloud Apps: VM, PCI, PC, WAS, WAF, CM, SYN, SAQ, TP, FIM,IOC, AI and SCA. In 2018, we introduced a number of new applications including CS, CI, CSA, CRI and CRA.We believe that our applications are easy to use and provide our customers with a high level of control because our applications are part ofone platform, share a common user interface, utilize the same scanners and agents, access the same collected data, and leverage the same userpermissions.Our customers can subscribe to one or more of our security and compliance Apps based on their initial needs and expand their subscriptionsover time to new areas within their organization or to additional Qualys solutions. We offer four editions of our Qualys Cloud Apps: Enterprise forlarge enterprises, Express for medium-sized businesses, Express Lite for small-sized businesses, and Consulting Edition for consultants,consulting organizations and Managed Service Providers (MSPs).Many of our customers use multiple Cloud Apps to develop a more complete understanding of their respective environment’s IT security andcompliance posture. The Qualys Cloud Platform currently provides the following Cloud Apps to our customers:IT SecurityVulnerability Management (VM): VM is an industry leading and award-winning solution that automates network auditing and vulnerabilitymanagement across an organization, including network discovery and mapping, asset management, vulnerability reporting and remediationtracking. Driven by our comprehensive knowledge base of known vulnerabilities, VM enables cost-effective protection against vulnerabilitieswithout substantial resource deployment.Threat Protection (TP): Thousands of new vulnerabilities are disclosed annually. With TP, customers can pinpoint their most critical threatsand identify what they need to remediate first. TP continuously correlates external threat information against a customer's vulnerabilities and ITasset inventory, so customers know which threats pose the greatest risk to their organization at any given time. As Qualys engineers continuouslyvalidate and rate new threats from internal and external sources, TP’s live feed displays the latest vulnerability disclosures and maps them tocustomers’ impacted IT assets. Customers can see the assets affected by each threat, and drill down into details.Continuous Monitoring (CM): Built on top of VM, CM is a next-generation cloud service that can detect network threats and unexpectedchanges before they turn into breaches. Whenever CM spots an anomaly in a network, it immediately sends targeted, informative alerts to the rightpeople for each situation and each machine. CM tracks what happens throughout public perimeters, internal networks, and cloud environments -anywhere in the world.Indication of Compromise (IOC): IOC delivers threat hunting, detects suspicious activity, and confirms the presence of known and unknownmalware for devices both on and off the network. From its single console, customers can monitor current and historical system activity for all on-premises servers, user endpoints, and cloud instances - even for assets that are currently offline or have been re-imaged by IT. IOC utilizes theCloud Agent to capture endpoint activity on files, processes, mutant handles, registries, and network connections, and uploads the data to theQualys Cloud Platform for storage, processing, and query.Certificate Assessment (CRA): CRA continuously assesses certificates and underlying SSL/TLS configurations and vulnerabilities acrossglobal IT assets to prevent downtime and outages, and mitigate risks from expired or vulnerable SSL/TLS certificates and configurations. Using astraight-forward methodology, it generates SSL Labs-8 Table of Contentscaliber certificate grades that allow non-experts to assess often-overlooked server SSL/TLS configurations. CRA also identifies out-of-policycertificates and features a fast and powerful search engine to look for specific certificates, vulnerabilities, configurations and grades. Dynamicdashboards create a holistic and contextual view of a certificate estate, and power automatically created downloadable reports. By continuouslycorrelating certificate and configuration information with vulnerability data, CRA provides remediation prioritization decisions are rooted in accurate,up-to-date, applicable data.Compliance MonitoringPolicy Compliance (PC): PC performs automated security configuration assessments on IT systems throughout a network, helping to reducerisk and continuously ensure compliance with internal policies and external regulations. PC leverages out-of-the-box library content to fast-trackcompliance assessments using industry-recommended best practices. PC also provides a centralized, interactive console for specifying baselinestandards for different hosts. By automating requirement evaluation against multiple standards for OSes, network devices, databases and serverapplications, PC enables the quick identification of security issues and works to prevent configuration drift. PC works to prioritize and trackremediation and exceptions, while demonstrating a repeatable auditable process for compliance management.PCI Compliance (PCI): PCI streamlines and automates compliance with PCI DSS (Payment Card Industry Data Security Standard)requirements for protecting the collection, storage, processing and transmission of cardholder data. As an Approved Scanning Vendor, Qualys hasbeen authorized by the PCI Security Standards Council to conduct the required quarterly scans. PCI scans all Internet-facing networks andsystems with Six Sigma (99.9996%) accuracy, generates reports and provides detailed patching instructions. An auto-submission featurecompletes the compliance process once remediation is completed.File Integrity Monitoring (FIM): FIM logs and centrally tracks file change events on common enterprise operating systems in organizations ofall sizes. FIM provides customers with a simple way to achieve centralized cloud-based visibility of activity resulting from normal patching andadministrative tasks, change control exceptions or violations, or malicious activity - then reports on that system activity as part of compliancemandates. FIM collects the critical details needed to quickly identify changes and root out activity that violates policy or is potentially malicious.FIM helps customers to comply with change control policy enforcement and change monitoring requirements.Security Configuration Assessment (SCA): SCA provides automatic assessment of IT assets’ configurations using the latest Center forInternet Security (CIS) Benchmarks for operating systems, databases, applications and network devices. SCA provides intuitive workflows forassessing, monitoring, reporting and remediating security-related configuration issues. SCA’s CIS assessments are provided via a web-based userinterface and delivered from the Qualys Cloud Platform, enabling centralized management with minimal deployment overhead. SCA users canautomatically create downloadable reports and view dashboards.Security Assessment Questionnaire (SAQ): SAQ automates and streamlines third-party and internal risk assessment processes, obviatingthe need to perform such processes manually via email and spreadsheets. SAQ easily designs surveys to assess procedural controls of ITsecurity policies and practices. SAQ automates the launch and monitoring of assessment campaigns, making the process agile, accurate,comprehensive, centralized, scalable and uniform across an organization. SAQ also provides tools for displaying, analyzing and acting oncollected data, enabling the assessment of compliance with industry standards, regulations and internal policies of third parties, like vendors andpartners, and of employees.Web Application SecurityWeb Application Scanning (WAS): WAS continuously discovers and catalogs web applications - including new and unknown ones - anddetects vulnerabilities and misconfigurations in web apps and APIs. Scaling to thousands of scans, it conducts incisive, thorough and precisetesting of browser-based web apps, mobile app backends, and Internet of things (IoT) services. Its seamless integration with the Qualys WebApplication Firewall (WAF) enables verification of attack protection and one click mitigation of vulnerabilities. WAS' powerful API enablesintegration with other systems and allows teams to detect issues within DevOps environments early in the application development process.Bundled malware detection capability with WAS uses reputational, behavioral, antivirus, and heuristic analyses to identify and alert on malwareinfecting a user's websites. By Integrating WAS with manual testing tools and bug bounty solutions, customers can build a comprehensive webapplication vulnerability testing program.9 Table of ContentsWeb Application Firewall (WAF): WAF permits the reduction of application security cost and complexity with a unified platform to prevent anyattempt to exploit vulnerabilities. Simple, scalable and adaptive, WAF enables the quick blocking of attacks, prevents disclosure of sensitiveinformation, and controls when and where customer applications are accessed. WAF and WAS work together seamlessly. Customers scan webapps with WAS, deploy one-click virtual patches if needed in WAF, and manage it all from a centralized cloud-based portal. WAF can be deployedin minutes on prem or in the cloud, as a virtual machine or a container, supports load-balancing as well as Transport Layer Security (TLS)offloading, and does not require special hardware.Global IT Asset ManagementAsset Inventory (AI): AI constantly gathers information on all assets, including system and hardware details, running services, open ports,installed software and user accounts. Asset discovery and inventory collection is done through a combination of Qualys network scanners andCloud Agents, which together collect comprehensive data from on-premises or cloud infrastructure as well as remote endpoints. In order to createconsistent and uniform asset data, AI normalizes raw discovery data to standardize every manufacturer name, product name, model and softwareversion using Qualys’ ever-evolving technology catalog as a reference. This catalog automatically extends IT asset inventory with non-discoverable metadata such as hardware and software release dates, end of life dates, and license categories. This new data layer allows teamsto detect issues such as unauthorized software, outdated hardware or end-of-life software, which can help properly support and secure criticalassets.CMDB Sync (SYN): SYN is a certified application that synchronizes Qualys AI data with ServiceNow’s Configuration Management system.Device changes are immediately transmitted to the Qualys Cloud Platform and then synchronized with ServiceNow. For customers, this means anend to unidentified and misclassified assets, and to data update delays, all of which increase chances of breaches. SYN provides real-time,comprehensive visibility of IT asset inventories enabling immediate detection of security and compliance risks.Certificate Inventory (CRI): CRI continuously scans global IT assets from a single console to discover internal and external certificatesissued from any certificate authority across all enterprise IT assets, both on premise and in the cloud. By doing so, it provides certificates can berenewed before they expire, which stops certificate-related outages and improves availability. It collects all certificate, vulnerability andconfiguration data required for certificate inventory and analysis. CRI also reveals how many certificates are out of compliance or do not followorganizational policies for key length, for signature algorithms or for the use of trusted and approved Certificate Authorities through the use ofhighly customizable dashboards and provides users a comprehensive overview of Qualys SSL Labs-caliber certificate grades for internal andexternally facing certificates.Cloud / Container SecurityCloud Inventory (CI): CI delivers continuous visibility into public cloud accounts. In one single-pane view, it inventories virtual machines,storage buckets, databases, security groups, Access Control Lists (ACLs), Elastic Load Balancers (ELBs) and users - across all regions, multipleaccounts and multiple cloud platforms. CI continuously tracks assets and enables users to quickly understand the topography of their cloudenvironment and uncover the root cause of incidents.Cloud Security Assessment (CSA): CSA provides a continuous assessment of the security posture of an organization’s cloud resourcesagainst misconfigurations, malicious behavior, and nonstandard deployments. CSA evaluates resources against CIS benchmarks and bestpractices to identify misconfigured storage buckets, security groups, Relational Database Service, exposing data and the resource forpublic exploitation. CSA correlates host vulnerabilities and compliance data into intelligent insights which allow users to quickly detect risksthroughout their complex cloud environments. With CSA, users gain real-time visibility into their up-to-date security and compliance posture ofpublic clouds in one single-pane view.Container Security (CS): CS delivers container-native visibility and protection throughout the entire lifecycle of containerized applications. Itincorporates scanning of container images for software composition and enforcement of hardened container stack configurations for continuouspolicy compliance, whether the images are on the build machines, in the container registries or in the runtime cluster nodes. CS uses a unique'layered-in' approach to provide deep visibility into all the application activities and automatically creates a behavior profile, which is enforced oneach container for runtime protection. By integrating with CI/CD pipelines and toolchains, CS enables DevSecOps processes and transparentenforcement of security and compliance without compromising the speed and agility of containers10 Table of Contentsand serverless deployment models. This leads to significant cost benefits for enterprises compared to certain legacy security solutions.Free ServicesWe also offer organizations of all sizes free security and compliance services based on the Qualys Cloud Platform:•Qualys Community Edition automatically gathers and analyzes security and compliance data from hybrid IT environments to provide acomplete, continuously updated, and instant view of monitored IT assets on-premises or in the cloud, as well as web apps, from a single-pane-of-glass interface. The Community Edition is limited to one user with data retention for three months.•Qualys CloudView continuously discovers and tracks assets and resources across public cloud deployments to provide users both real-time and historical views of cloud inventory. It collects metadata about cloud assets and resources to help users understand therelationships between public cloud assets and resources across different dimensions then discover their threat posture based on thoseattributes and relationships. CloudView is limited to three accounts per public cloud platform.•Qualys CertView inventories and assesses all Internet-facing certificates to generate SSL/TLS configuration grades, identifies thecertificate issuer and tracks certificate expirations to help stop expired and expiring certificates from interrupting critical businessfunctions.Our Growth StrategyWe intend to strengthen our leadership position as a trusted provider of cloud-based security and compliance solutions. The key elements ofour growth strategy are:•Continue to innovate and enhance our cloud platform and suite of solutions. We intend to continue to make significant investmentsin research and development to extend our cloud platform’s functionality by developing new security solutions and capabilities and furtherenhancing our existing suite of solutions. From inception through December 31, 2017, we have added the following solutions: VM, PCI,PC, WAS, WAF, CM, SYN, SAQ, TP, FIM, IOC, AI and SCA. In 2018, we introduced a number of new applications, including, CS, CI,CSA, CRI, and CRA.•Expand the use of our suite of solutions by our large and diverse customer base. With more than 12,200 customers and activeusers across many industries and geographies, we believe we have a significant opportunity to sell additional solutions to our customersand expand their use of our suite of solutions. Since typically our customers initially deploy one or two of our solutions in select parts oftheir IT infrastructures, our existing customers serve as a strong source of new sales as they expand their scope and increase theirsubscriptions or choose to adopt additional solutions from our integrated suite of IT security and compliance offerings. In this regard, wecontinue to expand our sales execution and marketing functions to increase adoption of our newly developed solutions among our existingcustomers.•Drive new customer growth and broaden our global reach. We are pursuing new customers by targeting key accounts, releasing freesecurity and compliance services and expanding both our sales and marketing organization and network of channel partners. We willcontinue to seek to make significant investments to encourage organizations to replace their existing security products with our cloudsolutions. We intend to expand our relationships with key security consulting organizations, managed security service providers and valueadded resellers to accelerate the adoption of our cloud platform. We seek to strengthen existing relationships as well as establish newrelationships to increase the distribution and market awareness of our cloud platform and target new geographic regions. We also plan topartner with such security providers that can host our Private Cloud offering within their data centers, helping us expand our reach in newmarkets and new geographies.•Selectively pursue technology acquisitions to bolster our capabilities and leadership position. We may explore acquisitions thatare complementary to and can expand the functionality of our cloud platform. We may also seek to acquire development teams tosupplement our own personnel and acquire technology to increase the breadth of our cloud-based security and compliance solutions. In2018, we acquired the software11 Table of Contentsassets of 1Mobility, a Singapore based company, allowing Qualys to provide enterprises of all sizes with the ability to create andcontinuously update an inventory of mobile devices on all versions of Android, iOS and Windows Mobile in their environment; and tocontinuously assess their security and compliance posture, while quarantining devices that are compromised or out-of-compliance. In2018, we also acquired Layered Insight, a provider of container native application protection, delivering insight into container images,adaptive analysis of running containers, and automated enforcement of the container environments.Our CustomersWe market and sell our solutions to enterprises, government entities and small and medium-sized businesses across a broad range ofindustries, including education, financial services, government, healthcare, insurance, manufacturing, media, retail, technology and utilities. As ofDecember 31, 2018, we had over 12,200 customers and active users in more than 130 countries, including a majority of each of the Forbes Global100 and Fortune 100. In each of 2018, 2017 and 2016, no one customer accounted for more than 10% of our revenues. In 2018, 2017 and 2016,67%, 70% and 71%, respectively, of our revenues were derived from customers in the United States. We sell our solutions to enterprises andgovernment entities primarily through our field sales force and to small and medium-sized businesses through our inside sales force. We generatea significant portion of sales through our channel partners, including managed service providers, value-added resellers and consulting firms in theUnited States and internationally.Sales and MarketingSalesWe market and sell our IT security and compliance solutions to customers directly through our sales teams as well as indirectly through ournetwork of channel partners.Our global sales force is organized into a field sales team, which focuses on enterprises, generally including organizations with more than5,000 employees, and an inside sales team, which focuses on small to medium-sized businesses, which generally include organizations with lessthan 5,000 employees. Both our field and inside sales teams are divided into three geographic regions, including the Americas; Europe, MiddleEast and Africa; and Asia-Pacific. We also further segment each of our sales teams into groups that focus on adding new customers or managingrelationships with existing customers.Our channel partners maintain relationships with their customers throughout the territories in which they operate and provide their customerswith services and third-party solutions to help meet those customers’ evolving security and compliance requirements. As such, these partnersoffer our IT security and compliance solutions in conjunction with one or more of their own products or services and act as a conduit through whichwe can connect with these prospective customers to offer our solutions. Our channel partners include security consulting organizations, managedservice providers and resellers, such as BT, Deutsche Telekom AG, Fujitsu, DXC Technology, IBM, Insight Technologies, Inc., Optiv Security,Inc., SecureWorks Corp., and Verizon Communications Inc.For sales involving a channel partner, the channel partner engages with the prospective customer directly and involves our sales team asneeded to assist in developing and closing an order. When a channel partner secures a sale, we sell the associated subscription to the channelpartner who in turn resells the subscription to the customer, with the channel partner earning a fee based on the total value of the order. Once theorder is completed, we provide these customers with direct access to our solutions and other associated back-office applications, enabling us toestablish a direct relationship as part of ensuring customer satisfaction with our solutions. At the end of the subscription term, the channel partnerengages with the customer to execute a renewal order, with our sales team providing assistance as required. In 2018, 2017 and 2016, 41%, 41%and 42%, respectively, of our revenues were generated by channel partners.MarketingOur marketing programs include a variety of online marketing, advertising, conferences, events, public relations activities and web-basedseminar campaigns targeted at key decision makers within our prospective customers.We have a number of marketing initiatives to build awareness and encourage customer adoption of our solutions. We offer free trials andservices to allow prospective customers to experience the quality of our solutions, to learn in detail about the features and functionality of ourcloud platform, and to quantify the potential benefits of our solutions.12 Table of ContentsCustomer SupportQualys Support delivers 24x7x365 day customer technical support from global centers located in Foster City, California; Raleigh, NorthCarolina; and Pune, India. We recruit senior level technical personnel and trained subject matter experts who work closely with engineering andoperations personnel to resolve issues quickly. Our security and compliance solutions can be deployed easily and are designed to be implementedand operated without the need for significant professional services. We also offer various training programs as part of our subscriptions to all of ourcustomers. In addition, we leverage the insights drawn from our customers to further improve the functionality of our security and compliancesolutions. Our mission is to ensure customer satisfaction and play a critical role in retaining and expanding our customer base.Research and Development and OperationsWe devote significant resources to maintain, enhance and add new functionality to our Qualys Cloud Platform and the integrated suite ofsolutions that we offer. Our development organization consists of agile engineering teams with substantial security expertise in specific areas ofour solutions. In addition to our development teams, we have also built a sophisticated research team focused on identifying threats anddeveloping signatures for vulnerabilities and compliance checks so that we can provide our customers with daily updates and enable them to scantheir assets for the latest threats. We conduct our research and development in the United States, France and India, which gives us access tosome of the best research and engineering talent in the world. Our focus remains to attract engineering talent as we continue to add new solutionsand improve existing ones.Our development team works closely with our customers and partners to gain valuable insights into their environments and gather feedbackfor threat research, product development and innovations. We typically release updates to our solutions, including enhancements and new featuresmultiple times a year, and we measure the quality of our scan results on a frequent basis in an effort to maintain the highest level of scanaccuracy.The modular architecture of our cloud platform enables our engineering teams to simultaneously work on different features, accelerating thedelivery of new functionalities to customers. Our research and development team also works collaboratively with our technical support team toensure customer satisfaction and with our sales team to accelerate the adoption of our solutions.Manufacturing AgreementOur physical appliances are provided by SYNNEX Corporation (SYNNEX), pursuant to a manufacturing services agreement dated March 1,2011. Under this agreement, SYNNEX manufactures, assembles and tests our physical scanner appliances. This agreement has an initial term ofone year, which is automatically renewed for additional one-year terms, unless terminated (i) at any time upon the mutual written agreement of usand SYNNEX, (ii) by either party upon 90 days or more written notice, (iii) upon written notice, subject to applicable cure periods, if the other partyhas materially breached its obligations under the agreement or (iv) by either party upon the other party seeking an order for relief under thebankruptcy laws of the United States or similar laws of any other jurisdiction, a composition with or assignment for the benefit of creditors, ordissolution or liquidation.Data Center AgreementsOur data center operations are provided by large third-party data center vendors and are located in the United States, Switzerland, theNetherlands and India. Our data center agreements have varying terms through 2020.CompetitionThe expanding capabilities of our security and compliance solutions have enabled us to address a growing array of opportunities in the cloudIT security and compliance market. We compete with a large and broad array of established and emerging vulnerability management vendors,compliance vendors and data security vendors in a highly fragmented and competitive environment.We compete with both large and small public companies, such as Carbon Black, Inc., FireEye, Inc., International Business MachinesCorporation, Micro Focus International plc, Rapid7, Inc., Symantec Corporation, and Tenable Holdings, Inc., as well as privately held securityproviders including Barracuda Networks Inc., BeyondTrust Software, Inc., CrowdStrike Inc., Tanium Inc., Tripwire, Inc. and Trustwave Holdings,Inc. We also seek to replace IT security and compliance solutions that organizations have developed internally. As we continue to extend ourcloud platform’s functionality by further developing security and compliance solutions, such as web application scanning and firewalls, we expectto face additional competition in these new markets. Our competitors may also attempt to further expand their presence in the IT security andcompliance market and compete more directly against one or more of our solutions.13 Table of ContentsWe believe that the principal competitive factors affecting the market for cloud-based security and compliance solutions include productfunctionality, breadth of product offerings, flexibility of delivery models, ease of deployment and use, total cost of ownership, scalability andperformance, customer support and extensibility of platform. We believe that our suite of solutions generally competes favorably with respect tothese factors. However, many of our primary competitors have greater name recognition, longer operating histories, more established customerrelationships, larger marketing budgets and significantly greater resources than we do.Intellectual PropertyWe rely on a combination of trade secrets, copyrights, patents and trademarks, as well as contractual protections, to establish and protectour intellectual property rights and protect our proprietary technology. As of February 22, 2019, we have sixteen issued patents, several pendingU.S. patent applications and an exclusive license to four U.S. patents, which was obtained in connection with our acquisition of Nemean in 2010.The inbound license remains in effect until the licensed patents are no longer enforceable, unless the applicable license agreement is firstterminated by us or terminated by the licensor for a breach of the agreement or if we undergo certain bankruptcy events. The licenses are currentlyexclusive and will remain exclusive so long as we make an appropriately-timed written election and pay an annual fixed royalty for ten yearsthereafter. These exclusive licenses are subject to the licensor’s reservation of certain rights in the patents and subject to the U.S. government’sreserved rights in the technology. We have a number of registered and unregistered trademarks. We require our employees, consultants and otherthird parties to enter into confidentiality and proprietary rights agreements and control access to software, documentation and other proprietaryinformation. We view our trade secrets and know-how as a significant component of our intellectual property assets, as we have spent yearsdesigning and developing the Qualys Cloud Platform, which we believe differentiates us from our competitors.We expect that software and other solutions in our industry may be subject to third-party infringement claims as the number of competitorsgrows and the functionality of products in different industry segments overlaps. Any of these third parties might make a claim of infringementagainst us at any time.EmployeesAs of December 31, 2018, we had 1,194 full-time employees, including 586 in research and development, 259 in sales and marketing, 231 inoperations and customer support and 118 in general and administrative. As of December 31, 2018, we had 418 employees in the United Statesand 776 employees internationally. None of our U.S. employees are covered by collective bargaining agreements. Employees in certain Europeancountries have collective bargaining arrangements at the national level. We believe our employee relations are good and we have not experiencedany work stoppages. As of December 31, 2018, approximately 65% of our employees were located outside the United States, with 54% of ouremployees located in Pune, India.Available InformationOur principal executive offices are located at 919 E. Hillsdale Blvd., 4th Floor, Foster City, California 94404. The telephone number of ourprincipal executive offices is (650) 801-6100, and our main corporate website is www.qualys.com. Information contained on, or that can beaccessed through, our website, does not constitute part of this Annual Report on Form 10-K and inclusion of our website address in this AnnualReport on Form 10-K is an inactive textual reference only.We make available our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K and amendments tothose reports filed or furnished pursuant to Section 13(a) or Section 15(d) of the Securities Exchange Act of 1934, as amended, free of charge onour website, www.qualys.com as soon as reasonably practicable after they are electronically filed with or furnished to the Securities and ExchangeCommission, or SEC. Additionally, copies of materials filed by us with the SEC may be accessed at the SEC's website, www.sec.gov.14 Table of ContentsItem 1A.Risk FactorsAn investment in our common stock involves a high degree of risk. You should carefully consider the risks and uncertainties describedbelow, and all other information contained in this Annual Report on Form 10-K, including our consolidated financial statements and the relatednotes, before making a decision to invest in our common stock. Our business, operating results, financial condition, or prospects could bematerially and adversely affected by any of these risks and uncertainties. In that case, the trading price of our common stock could decline, andyou might lose all or part of your investment. In addition, the risks and uncertainties discussed below are not the only ones we face. Our business,operating results, financial performance or prospects could also be harmed by risks and uncertainties not currently known to us or that we currentlydo not believe are material.Subscriptions to our Vulnerability Management solutions generate most of our revenues, and if we are unable to continue to renew andgrow subscriptions for these solutions, our operating results would suffer.We derived approximately 74%, 74% and 76% of our revenues from subscriptions to our VM solutions for the years ended December 31,2018, 2017 and 2016, respectively. In 2015 and prior 10-Q and 10-K filings, we had included all revenues from scanners and credits for prepaidservices in our VM solutions revenues. In the fourth quarter of 2016, we changed the methodology to allocate revenues from scanners and creditsacross our products.We expect to continue to derive a significant majority of our revenues from subscriptions to our VM solutions. As a result, the marketdemand for our VM solutions is critical to our continued success. Demand for these solutions is affected by a number of factors beyond ourcontrol, including continued market acceptance of our solution for existing and new use cases, the timing of development and release of newproducts or services by our competitors, technological change, and growth or contraction in our market. Our inability to renew or increasesubscriptions for this solution or a decline in price of this solution would harm our business and operating results more seriously than if we derivedsignificant revenues from a variety of solutions.Our quarterly operating results may vary from period to period, which could result in our failure to meet expectations with respect tooperating results and cause the trading price of our stock to decline.Our operating results have historically varied from period to period, and we expect that they will continue to do so as a result of a number offactors, many of which are outside of our control, including:•the level of demand for our solutions;•publicity regarding security breaches generally and the level of perceived threats to IT security;•expenses associated with our existing and new products and services;•changes in customer renewals of our solutions;•the extent to which customers subscribe for additional solutions;•seasonal buying patterns of our customers;•security breaches, technical difficulties or interruptions with our service;•changes in the growth rate of the IT security and compliance market;•the timing and success of new product or service introductions by us or our competitors or any other changes in the competitivelandscape of our industry, including consolidation among our competitors;•the introduction or adoption of new technologies that compete with our solutions;•decisions by potential customers to purchase IT security and compliance products or services from other vendors;•the amount and timing of operating costs and capital expenditures related to the operations and expansion of our business;•the timing of sales commissions relative to the recognition of revenues;•the announcement or adoption of new regulations and policy mandates or changes to existing regulations and policy mandates;15 Table of Contents•failure of our products and services to operate as designed;•price competition;•the length of our sales cycle for our products and services;•insolvency or credit difficulties confronting our customers, affecting their ability to purchase or pay for our solutions;•timely invoicing or changes in billing terms of customers;•timing of deals signed within the quarter;•pace and cost of hiring employees;•changes in foreign currency exchange rates;•general economic conditions, both domestically and in the foreign markets in which we sell our solutions;•future accounting pronouncements or changes in our accounting policies;•our ability to integrate any products or services that we may acquire in the future into our product suite or migrate existing customers ofany companies that we may acquire in the future to our products and services;•our effective tax rate;•the amount and timing of income tax benefits that we recognize resulting from excess tax benefits related to stock-based compensation;•the timing of expenses related to the development or acquisition of technologies, services or businesses; and•potential goodwill and intangible asset impairment charges associated with acquired businesses.Further, the interpretation and application of international laws and regulations in many cases is uncertain, and our legal and regulatoryobligations in foreign jurisdictions are subject to frequent and unexpected changes, including the potential for various regulatory or othergovernmental bodies to enact new or additional laws or regulations or to issue rulings that invalidate prior laws or regulations.For example, "Brexit" could also lead to further legislative and regulatory changes. A Data Protection Act that substantially implements theEuropean Union’s General Data Protection Regulation has been implemented in the United Kingdom, effective in May 2018. It is unclear, however,how United Kingdom data protection laws or regulations will develop in the medium to longer term, and how data transfers to and from the UnitedKingdom will be regulated.Each factor above or discussed elsewhere in this Annual Report on Form 10-K or the cumulative effect of some of these factors may result influctuations in our operating results. This variability and unpredictability could result in our failure to meet expectations with respect to operatingresults, or those of securities analysts or investors, for a particular period. In addition, a significant percentage of our operating expenses are fixedin nature and based on forecasted trends in revenues. Accordingly, in the event of shortfalls in revenues, we are generally unable to mitigate thenegative impact on margins in the short term by reducing our operating expenses. If we fail to meet or exceed expectations for our operatingresults for these or any other reasons, the trading price of our common stock could fall and we could face costly lawsuits, including securitiesclass action suits.16 Table of ContentsIf we do not successfully anticipate market needs and opportunities or are unable to enhance our solutions and develop new solutionsthat meet those needs and opportunities on a timely or cost-effective basis, we may not be able to compete effectively and our businessand financial condition may be harmed.The IT security and compliance market is characterized by rapid technological advances, customer price sensitivity, short product andservice life cycles, intense competition, changes in customer requirements, frequent new product introductions and enhancements and evolvingindustry standards and regulatory mandates. Any of these factors could create downward pressure on pricing and gross margins, and couldadversely affect our renewal rates, as well as our ability to attract new customers. Our future success will depend on our ability to enhanceexisting solutions, introduce new solutions on a timely and cost-effective basis, meet changing customer needs, extend our core technology intonew applications, and anticipate and respond to emerging standards and business models. We must also continually change and improve oursolutions in response to changes in operating systems, application software, computer and communications hardware, networking software, datacenter architectures, programming tools and computer language technology.We may not be able to anticipate future market needs and opportunities or develop enhancements or new solutions to meet such needs oropportunities in a timely manner or at all. The market for cloud solutions for IT security and compliance continues to evolve, and it is uncertainwhether our new solutions will gain market acceptance.Our solution enhancements or new solutions could fail to attain sufficient market acceptance for many reasons, including:•failure to timely meet market demand for product functionality;•inability to identify and provide intelligence regarding the attacks or techniques used by cyber-attackers;•inability to inter-operate effectively with the database technologies, file systems or web applications of our prospective customers;•defects, errors or failures;•delays in releasing our enhancements or new solutions;•negative publicity about their performance or effectiveness;•introduction or anticipated introduction of products by our competitors;•poor business conditions, causing customers to delay IT security and compliance purchases;•easing or changing of external regulations related to IT security and compliance; and•reluctance of customers to purchase cloud solutions for IT security and compliance.Furthermore, diversifying our solutions and expanding into new IT security and compliance markets will require significant investment andplanning, require that our research and development and sales and marketing organizations develop expertise in these new markets, bring us moredirectly into competition with IT security compliance providers that may be better established or have greater resources than we do, requireadditional investment of time and resources in the development and training of our channel partners and entail significant risk of failure.If we fail to anticipate market requirements or fail to develop and introduce solution enhancements or new solutions to satisfy thoserequirements in a timely manner, such failure could substantially decrease or delay market acceptance and sales of our present and futuresolutions and cause us to lose existing customers or fail to gain new customers, which would significantly harm our business, financial conditionand results of operations.17 Table of ContentsIf we fail to continue to effectively scale and adapt our platform to meet the performance and other requirements of our customers, ouroperating results and our business would be harmed.Our future growth depends upon our ability to continue to meet the expanding needs of our customers as their use of our cloud platformgrows. As these customers gain more experience with our solutions, the number of users and the number of locations where our solutions arebeing accessed may expand rapidly in the future. In order to ensure that we meet the performance and other requirements of our customers, weintend to continue to make significant investments to develop and implement new proprietary and third-party technologies at all levels of our cloudplatform. These technologies, which include databases, applications and server optimizations, and network and hosting strategies, are oftencomplex, new and unproven. We may not be successful in developing or implementing these technologies. To the extent that we do not effectivelyscale our platform to maintain performance as our customers expand their use of our platform, our operating results and our business may beharmed.If we are unable to sell subscriptions to additional solutions, our future revenue growth may be harmed and our business may suffer.We will need to increase the revenues that we derive from our current and future solutions other than VM for our business and revenues togrow as we expect. Revenues from our other solutions such as Policy Compliance, PCI Compliance, Security Assessment Questionnaire, WebApplication Scanning, and Web Application Firewall have been relatively modest compared to revenues from our VM solutions. Our future successdepends in part on our ability to sell subscriptions to these additional solutions to existing and new customers. This may require more costly salesand marketing efforts and may not result in additional sales. If our efforts to sell subscriptions to additional solutions to existing and newcustomers are not successful, our business may suffer.If the market for cloud solutions for IT security and compliance does not evolve as we anticipate, our revenues may not grow and ouroperating results would be harmed.Our success depends to a significant extent on the willingness of organizations to increase their use of cloud solutions for their IT securityand compliance. To date, some organizations have been reluctant to use cloud solutions because they have concerns regarding the risksassociated with the reliability or security of the technology delivery model associated with these solutions. If other cloud service providersexperience security incidents, loss of customer data, disruptions in service delivery or other problems, the market for cloud solutions as a whole,including our solutions, may be negatively impacted. Moreover, many organizations have invested substantial personnel and financial resources tointegrate on-premise software into their businesses, and as a result may be reluctant or unwilling to migrate to a cloud solution. Organizations thatuse on-premise security products, such as network firewalls, security information and event management products or data loss preventionsolutions, may also believe that these products sufficiently protect their IT infrastructure and deliver adequate security. Therefore, they maycontinue spending their IT security budgets on these products and may not adopt our security and compliance solutions in addition to or as areplacement for such products.If customers do not recognize the benefits of our cloud solutions over traditional on-premise enterprise software products, and as a result weare unable to increase sales of subscriptions to our solutions, then our revenues may not grow or may decline, and our operating results would beharmed.Our current research and development efforts may not produce successful products or enhancements to our platform that result insignificant revenue, cost savings or other benefits in the near future.We must continue to dedicate significant financial and other resources to our research and development efforts if we are to maintain ourcompetitive position. However, developing products and enhancements to our platform is expensive and time consuming, and there is noassurance that such activities will result in significant new marketable products or enhancements to our platform, design improvements, costsavings, revenue or other expected benefits. If we spend significant resources on research and development and are unable to generate anadequate return on our investment, our business and results of operations may be materially and adversely affected.Our platform, website and internal systems may be subject to intentional disruption or other security incidents that could result inliability and adversely impact our reputation and future sales.We and our service providers could be a target of cyber-attacks or other malfeasance designed to impede the performance of our solutions,penetrate our network security or the security of our cloud platform or our internal18 Table of Contentssystems, misappropriate proprietary information and/or cause interruptions to our services. Our solutions, platforms, and system may also suffersecurity incidents as a result of non-technical issues, including intentional or inadvertent breaches by our employees or service providers.Because our operations involve providing IT security solutions to our customers, we may be targeted for cyber-attacks and other securityincidents. If an actual or perceived breach of our security measures or those of our service providers occurs, it could adversely affect the marketperception of our solutions, negatively affecting our reputation, and may expose us to the loss of information, litigation, regulatory actions andpossible liability. Any such actual or perceived security breach could also divert the efforts of our technical and management personnel. Inaddition, any such actual or perceived security breach could impair our ability to operate our business and provide solutions to our customers. Ifthis happens, our reputation could be harmed, our revenues could decline and our business could suffer.Our business depends substantially on retaining our current customers, and any reduction in our customer renewals or revenues fromsuch customers could harm our future operating results.We offer our Qualys Cloud Platform and integrated suite of solutions pursuant to a software-as-a-service model, and our customers purchasesubscriptions from us that are generally one year in length. Our customers have no obligation to renew their subscriptions after their subscriptionperiod expires, and they may not renew their subscriptions at the same or higher levels or at all. As a result, our ability to grow depends in part oncustomers renewing their existing subscriptions and purchasing additional subscriptions and solutions. Our customers may choose not to renewtheir subscriptions to our solutions or purchase additional solutions due to a number of factors, including their satisfaction or dissatisfaction withour solutions, the prices of our solutions, the prices of products or services offered by our competitors, reductions in our customers’ spendinglevels due to the macroeconomic environment or other factors. If our customers do not renew their subscriptions to our solutions, renew on lessfavorable terms, or do not purchase additional solutions or subscriptions, our revenues may grow more slowly than expected or decline and ourresults of operations may be harmed.If we are unable to continue to attract new customers and grow our customer base, our growth could be slower than we expect and ourbusiness may be harmed.We believe that our future growth depends in part upon increasing our customer base. Our ability to achieve significant growth in revenues inthe future will depend, in large part, upon continually attracting new customers and obtaining subscription renewals to our solutions from thosecustomers. If we fail to attract new customers our revenues may grow more slowly than expected and our business may be harmed.Our sales cycle can be long and unpredictable, and our sales efforts require considerable time and expense. As a result, revenues mayvary from period to period, which may cause our operating results to fluctuate and could harm our business.The timing of sales of subscriptions for our solutions can be difficult to forecast because of the length and unpredictability of our sales cycle,particularly with large transactions. We sell subscriptions to our security and compliance solutions primarily to IT departments that are managing agrowing set of user and compliance demands, which has increased the complexity of customer requirements to be met and confirmed during thesales cycle and prolonged our sales cycle. Further, the length of time that potential customers devote to their testing and evaluation, contractnegotiation and budgeting processes varies significantly, which has also made our sales cycle long and unpredictable. The length of the salescycle for our solutions typically ranges from six to twelve months but can be more than eighteen months. In addition, we might devote substantialtime and effort to a particular unsuccessful sales effort, and as a result we could lose other sales opportunities or incur expenses that are notoffset by an increase in revenues, which could harm our business.Adverse economic conditions or reduced IT spending may adversely impact our business.Our business depends on the overall demand for IT and on the economic health of our current and prospective customers. Economicweakness, customer financial difficulties, and constrained spending on IT security may result in decreased revenue and earnings. Such factorscould make it difficult to accurately forecast our sales and operating results and could negatively affect our ability to provide accurate forecasts toour contract manufacturers. In addition, continued governmental budgetary challenges in the United States and Europe and geopolitical turmoil inmany parts of the world have and may continue to put pressure on global economic conditions and overall spending on IT security. Generaleconomic weakness may also lead to longer collection cycles for payments due from our customers, an increase in customer bad debt,restructuring initiatives and associated expenses, and impairment of investments.19 Table of ContentsFurthermore, the continued weakness and uncertainty in worldwide credit markets, including the sovereign debt situation in certain countries in theEuropean Union, may adversely impact our customers' available budgetary spending, which could lead to delays in planned purchases of oursolutions.Additionally, concerns regarding the effects of the "Brexit" decision, uncertainties related to changes in public policies such as domestic andinternational regulations, taxes or international trade agreements as well as geopolitical turmoil and other disruptions to global and regionaleconomies and markets in many parts of the world, have and may continue to put pressure on global economic conditions and overall spending onIT security. We have operations, as well as current and potential customers, throughout most of Europe. If economic conditions in Europe andother key markets for our platform continue to remain uncertain or deteriorate further, many customers may delay or reduce their IT spending.Uncertainty about future economic conditions also makes it difficult to forecast operating results and to make decisions about futureinvestments. Future or continued economic weakness for us or our customers, failure of our customers and markets to recover from suchweakness, customer financial difficulties, and reductions in spending on IT security could have a material adverse effect on demand for ourplatform and consequently on our business, financial condition and results of operations.Our security and compliance solutions are delivered from seven data centers, and any disruption of service at these facilities wouldinterrupt or delay our ability to deliver our solutions to our customers which could reduce our revenues and harm our operating results.We currently host substantially all of our solutions from third-party data centers located in the United States, Switzerland, the Netherlandsand India. These facilities are vulnerable to damage or interruption from earthquakes, hurricanes, floods, fires, cybersecurity attacks, terroristattacks, employee negligence, power losses, telecommunications failures and similar events. The facilities also could be subject to break-ins,sabotage, intentional acts of vandalism and other misconduct. The occurrence of a natural disaster, an act of terrorism or misconduct, a decisionto close the facilities without adequate notice or other unanticipated problems could result in interruptions in our services.Some of our data centers are not currently redundant and we may not be able to rapidly move our customers from one data center to another,which may increase delays in the restoration of our service for our customers if an adverse event occurs. We have added data center facilities toprovide additional capacity for our cloud platform and to enable disaster recovery. We continue to build out these facilities; however, theseadditional facilities may not be operational in the anticipated time-frame and we may incur unplanned expenses.Additionally, our existing data center facilities providers have no obligations to renew their agreements with us on commercially reasonableterms, or at all. If we are unable to renew our agreements with the facilities providers on commercially reasonable terms or if in the future we addadditional data center facility providers, we may experience costs or downtime in connection with the loss of an existing facility or the transfer to,or addition of, new data center facilities.Any disruptions or other performance problems with our solutions could harm our reputation and business and may damage our customers’businesses. Interruptions in our service delivery might reduce our revenues, cause us to issue credits to customers, subject us to potential liabilityand cause customers to terminate their subscriptions or not renew their subscriptions.If we are unable to increase market awareness of our company and our new solutions, our revenues may not continue to grow, or maydecline.We have a limited operating history, particularly in certain markets and solution offerings, and we believe that we need to continue to developmarket awareness in the IT security and compliance market. Market awareness of our capabilities and solutions is essential to our continuedgrowth and success in all of our markets, particularly for the large enterprise, service provider and government markets. If our marketing programsare not successful in creating market awareness of our company and our full suite of solutions, our business, financial condition and results ofoperations may be adversely affected, and we may not be able to achieve our expected growth.We face competition in our markets, and we may lack sufficient financial or other resources to maintain or improve our competitiveposition.20 Table of ContentsWe compete with a large range of established and emerging vulnerability management vendors, compliance vendors and data securityvendors in a highly fragmented and competitive environment. We face significant competition for each of our solutions from companies with broadproduct suites and greater name recognition and resources than we have, as well as from small companies focused on specialized securitysolutions.We compete with large and small public companies, such as Carbon Black, Inc., FireEye, Inc., International Business Machines Corporation,Micro Focus International plc, Rapid7, Inc., Symantec Corporation, and Tenable Holdings, Inc., as well as privately held security providersincluding Barracuda Networks Inc., BeyondTrust Software, Inc., CrowdStrike Inc., Tanium Inc., Tripwire, Inc. and Trustwave Holdings, Inc. Wealso seek to replace IT security and compliance solutions that organizations have developed internally. As we continue to extend our cloudplatform’s functionality by further developing security and compliance solutions, such as web application scanning and firewalls, we expect to faceadditional competition in these new markets. Our competitors may also attempt to further expand their presence in the IT security and compliancemarket and compete more directly against one or more of our solutions.We believe that the principal competitive factors affecting our markets include product functionality, breadth of offerings, flexibility of deliverymodels, ease of deployment and use, total cost of ownership, scalability and performance, customer support and extensibility of platform. Many ofour existing and potential competitors have competitive advantages, including:•greater brand name recognition;•larger sales and marketing budgets and resources;•broader distribution networks and more established relationships with distributors and customers;•access to larger customer bases;•greater customer support resources;•greater resources to make acquisitions;•greater resources to develop and introduce products that compete with our solutions;•greater resources to meet relevant regulatory requirements; and•substantially greater financial, technical and other resources.As a result, our competitors may be able to respond more quickly and effectively than we can to new or changing opportunities, technologies,standards or customer requirements. With the introduction of new technologies, the evolution of our service and new market entrants, we expectcompetition to intensify in the future.In addition, some of our larger competitors have substantially broader product offerings and can bundle competing products and services withother software offerings. As a result, customers may choose a bundled product offering from our competitors, even if individual products havemore limited functionality than our solutions. These competitors may also offer their products at a lower price as part of this larger sale, whichcould increase pricing pressure on our solutions and cause the average sales price for our solutions to decline. These larger competitors are alsooften in a better position to withstand any significant reduction in capital spending, and will therefore not be as susceptible to economic downturns.Furthermore, our current and potential competitors may establish cooperative relationships among themselves or with third parties that mayfurther enhance their resources and product and services offerings in the markets we address. In addition, current or potential competitors may beacquired by third parties with greater available resources. As a result of such relationships and acquisitions, our current or potential competitorsmight be able to adapt more quickly to new technologies and customer needs, devote greater resources to the promotion or sale of their productsand services, initiate or withstand substantial price competition, take advantage of other opportunities more readily or develop and expand theirproduct and service offerings more quickly than we do. For all of these reasons, we may not be able to compete successfully against our currentor future competitors.If our solutions fail to help our customers achieve and maintain compliance with regulations and industry standards, our revenues andoperating results could be harmed.21 Table of ContentsWe generate a portion of our revenues from solutions that help organizations achieve and maintain compliance with regulations and industrystandards. For example, many of our customers subscribe to our security and compliance solutions to help them comply with the securitystandards developed and maintained by the Payment Card Industry Security Standards Council, or the PCI Council, which apply to companies thatstore cardholder data. Industry organizations like the PCI Council may significantly change their security standards with little or no notice,including changes that could make their standards more or less onerous for businesses. Governments may also adopt new laws or regulations, ormake changes to existing laws or regulations, that could impact the demand for or value of our solutions.If we are unable to adapt our solutions to changing regulatory standards in a timely manner, or if our solutions fail to assist with or expediteour customers’ compliance initiatives, our customers may lose confidence in our solutions and could switch to products offered by ourcompetitors. In addition, if regulations and standards related to data security, vulnerability management and other IT security and compliancerequirements are relaxed or the penalties for non-compliance are changed in a manner that makes them less onerous, our customers may viewgovernment and industry regulatory compliance as less critical to their businesses, and our customers may be less willing to purchase oursolutions. In any of these cases, our revenues and operating results could be harmed.We may not maintain profitability in the future.We may not be able to sustain or increase our growth or maintain profitability in the future. We plan to continue to invest in our infrastructure,new solutions, research and development and sales and marketing, and as a result, we cannot assure you that we will maintain profitability. Wemay incur losses in the future for a number of reasons, including without limitation, the other risks and uncertainties described in this AnnualReport on Form 10-K. Additionally, we may encounter unforeseen operating expenses, difficulties, complications, delays and other unknownfactors that may result in losses in future periods. If our revenue growth does not meet our expectations in future periods, our financialperformance may be harmed and we may not again achieve or maintain profitability in the future.The sales prices of our solutions are subject to competitive pressures and may decrease, which may reduce our gross profits andadversely impact our financial results.The sales prices for our solutions may decline for a variety of reasons, including competitive pricing pressures, discounts, a change in our mixof solutions and subscriptions, anticipation of the introduction of new solutions or subscriptions, or promotional programs. Competition continues toincrease in the market segments in which we participate, and we expect competition to further increase in the future, thereby leading to increasedpricing pressures. Larger competitors with more diverse product and service offerings may reduce the price of products or subscriptions thatcompete with ours or may bundle them with other products and subscriptions. Additionally, although we price our products and subscriptionsworldwide in U.S. Dollars, Euros, British Pounds and Japanese Yen, currency fluctuations in certain countries and regions may negatively impactactual prices that partners and customers are willing to pay in those countries and regions, or the effective prices we realize in our reportingcurrency. We cannot assure you that we will be successful in developing and introducing new offerings with enhanced functionality on a timelybasis, or that our new product and subscription offerings, if introduced, will enable us to maintain our prices and gross profits at levels that willallow us to maintain positive gross margins and profitability.If our solutions fail to detect vulnerabilities or incorrectly detect vulnerabilities, our brand and reputation could be harmed, which couldhave an adverse effect on our business and results of operations.If our solutions fail to detect vulnerabilities in our customers’ IT infrastructures, or if our solutions fail to identify and respond to new andincreasingly complex methods of attacks, our business and reputation may suffer. There is no guarantee that our solutions will detect allvulnerabilities. Additionally, our security and compliance solutions may falsely detect vulnerabilities or threats that do not actually exist. Forexample, some of our solutions rely on information on attack sources aggregated from third-party data providers who monitor global maliciousactivity originating from a variety of sources, including anonymous proxies, specific IP addresses, botnets and phishing sites. If the informationfrom these data providers is inaccurate, the potential for false indications of security vulnerabilities increases. These false positives, while typicalin the industry, may impair the perceived reliability or usability of our solutions and may therefore adversely impact market acceptance of oursolutions and could result in negative publicity, loss of customers and sales, increased costs to remedy any incorrect information or problem, orclaims by aggrieved parties. Similar issues may be generated by the misuse of our tools to identify and exploit vulnerabilities.22 Table of ContentsIn addition, our solutions do not currently extend to cover mobile devices or personal devices that employees may bring into an organization.As such, our solutions would not identify or address vulnerabilities in mobile devices, such as mobile phones or tablets, or personal devices, andour customers’ IT infrastructures may be compromised by attacks that infiltrate their networks through such devices.An actual or perceived security breach or theft of the sensitive data of one of our customers, regardless of whether the breach is attributableto the failure of our solutions, could adversely affect the market’s perception of our security solutions.Incorrect or improper implementation or use of our solutions could result in customer dissatisfaction and harm our business andreputation.Our solutions are deployed in a wide variety of IT environments, including large-scale, complex infrastructures. If our customers are unable toimplement our solutions successfully, customer perceptions of our platform may be impaired or our reputation and brand may suffer. Ourcustomers have in the past inadvertently misused our solutions, which triggered downtime in their internal infrastructure until the problem wasresolved. Any misuse of our solutions could result in customer dissatisfaction, impact the perceived reliability of our solutions, result in negativepress coverage, negatively affect our reputation and harm our financial results.Undetected software errors or flaws in our cloud platform could harm our reputation or decrease market acceptance of our solutions,which would harm our operating results.Our solutions may contain undetected errors or defects when first introduced or as new versions are released. We have experienced theseerrors or defects in the past in connection with new solutions and solution upgrades and we expect that these errors or defects will be found fromtime to time in the future in new or enhanced solutions after commercial release of these solutions. Since our customers use our solutions forsecurity and compliance reasons, any errors, defects, disruptions in service or other performance problems with our solutions may damage ourcustomers’ business and could hurt our reputation. If that occurs, we may incur significant costs, the attention of our key personnel could bediverted, our customers may delay or withhold payment to us or elect not to renew, or other significant customer relations problems may arise. Wemay also be subject to liability claims for damages related to errors or defects in our solutions. A material liability claim or other occurrence thatharms our reputation or decreases market acceptance of our solutions may harm our business and operating results.Our solutions could be used to collect and store personal information of our customers’ employees or customers, and therefore privacyand other data handling concerns could result in additional cost and liability to us or inhibit sales of our solutions.We collect the names and email addresses of our customers in connection with subscriptions to our solutions. Additionally, the data that oursolutions collect to help secure and protect the IT infrastructure of our customers may include additional personal or confidential information of ourcustomers’ employees and their customers. Personal privacy has become a significant issue in the United States and in many other countrieswhere we offer our solutions. The regulatory framework for privacy issues worldwide is currently evolving and is likely to remain uncertain for theforeseeable future. Many federal, state and foreign government bodies and agencies have adopted or are considering adopting laws andregulations regarding the collection, use, disclosure and retention of personal information. In the United States, these include, for example, rulesand regulations promulgated under the authority of the Federal Trade Commission, the Health Insurance Portability and Accountability Act of 1996,the Gramm-Leach-Bliley Act, and state breach notification laws. Internationally, virtually every jurisdiction in which we operate has established itsown data security and privacy legal framework with which we or our customers must comply, including the Data Protection Directive established inthe European Union and the Federal Data Protection Act passed in Germany.These privacy, data protection and information security laws and regulations may result in ever-increasing regulatory and public scrutiny andescalating levels of enforcement and sanctions. Additionally, new laws and regulations relating to privacy and data protection continue to beproposed and enacted. For example, the European Union has adopted the General Data Protection Regulation, or GDPR, to supersede the DataProtection Directive. This regulation, which took full effect on May 25, 2018, causes EU data protection requirements to be more stringent andprovides for greater penalties. Noncompliance with the GDPR can trigger fines of up to €20 million or 4% of global annual revenues, whichever ishigher. Additionally, California recently enacted legislation, the California Consumer Privacy Act (“CCPA”), that will, among other things, requirecovered companies to provide new disclosures to California consumers, and afford such consumers new abilities to opt-out of certain sales ofpersonal information, when it goes23 Table of Contentsinto effect on January 1, 2020. The CCPA was amended in September 2018, and it is unclear whether further modifications will be made to thislegislation or how it will be interpreted. We cannot yet predict the impact of the CCPA on our business or operations, but it may require us tomodify our data processing practices and policies and to incur substantial costs and expenses in an effort to comply.The privacy, data protection, and information security laws and regulations we must comply with also are subject to change. For example, inJune 2016, United Kingdom voters approved an exit from the European Union, commonly referred to as “Brexit,” which could also lead to furtherlegislative and regulatory changes. Additionally, an October 2015 ruling of the Court of Justice of the European Union invalidated the U.S.-EU SafeHarbor Framework as a method of compliance with European restrictions regarding the transfer of personal data outside of the European EconomicArea, or EEA. U.S. and EU authorities reached a political agreement in February 2016 regarding a new means for legitimizing personal datatransfers from the EEA to the U.S., the EU-U.S. Privacy Shield Framework, and we have joined the EU-U.S. Privacy Shield Framework and arelated program, the Swiss-U.S. Privacy Shield Framework. The EU-U.S. Privacy Shield Framework is subject to legal challenge, however, and itor the Swiss-U.S. Privacy Shield Framework may be modified or invalidated. We may be unsuccessful in maintaining legitimate means for ourtransfer and receipt of personal data from the EEA or Switzerland. We may experience reluctance or refusal by current or prospective Europeancustomers to use our products, and we may find it necessary or desirable to make further changes to our handling of personal data of Europeanresidents.In addition to laws and regulations, privacy advocacy and industry groups or other private parties may propose new and different privacystandards that either legally or contractually apply to us. Because the interpretation and application of privacy and data protection laws,regulations, standards and contractual obligations are uncertain, it is possible that they may be interpreted and applied in a manner that is, orperceived to be, inconsistent with our data management practices or the features of our solutions. If so, in addition to the possibility of regulatoryinvestigations and enforcement actions, fines, lawsuits and other claims, other forms of injunctive or operations-limiting relief, and damage to ourreputations and loss of goodwill, we could be required to fundamentally change our business activities and practices or modify our solutions andmay face limitations in our ability to develop new solutions and features, any of which could have an adverse effect on our business. Any inabilityto adequately address privacy concerns, even if unfounded, or any actual or perceived inability to comply with applicable privacy or data protectionlaws, regulations and privacy standards, could result in cost and liability to us, damage our reputation, inhibit sales of subscriptions and harm ourbusiness.Furthermore, the costs of compliance with, and other burdens imposed by, the laws, regulations, and privacy standards that are applicable tothe businesses of our customers may limit the use and adoption of, and reduce the overall demand for, our solutions. Privacy concerns, whethervalid or not valid, may inhibit market adoption of our solutions particularly in certain industries and foreign countries.If we are unable to continue the expansion of our sales force, sales of our solutions and the growth of our business would be harmed.We believe that our growth will depend, to a significant extent, on our success in recruiting and retaining a sufficient number of qualified salespersonnel and their ability to obtain new customers, manage our existing customer base and expand the sales of our newer solutions. We plan tocontinue to expand our sales force and make significant investment in our sales and marketing activities. Our recent hires and planned hires maynot become as productive as quickly as we would like, and we may be unable to hire or retain sufficient numbers of qualified individuals in thefuture in the competitive markets where we do business. Competition for highly skilled personnel is frequently intense and we may not be able tocompete for these employees. If we are unable to recruit and retain a sufficient number of productive sales personnel, sales of our solutions andthe growth of our business may be harmed. Additionally, if our efforts do not result in increased revenues, our operating results could be negativelyimpacted due to the upfront operating expenses associated with expanding our sales force.A significant portion of our customers, channel partners and employees are located outside of the United States, which subjects us to anumber of risks associated with conducting international operations, and if we are unable to successfully manage these risks, ourbusiness and operating results could be harmed.We market and sell subscriptions to our solutions throughout the world and have personnel in many parts of the world. In addition, we havesales offices and research and development facilities outside the United States and we conduct, and expect to continue to conduct, a significantamount of our business with organizations that are located24 Table of Contentsoutside the United States, particularly in Europe and Asia. Therefore, we are subject to risks associated with having international sales andworldwide operations, including:•foreign currency exchange fluctuations;•trade and foreign exchange restrictions;•economic or political instability in foreign markets;•greater difficulty in enforcing contracts, accounts receivable collection and longer collection periods;•changes in regulatory requirements;•tax laws (including U.S. taxes on foreign subsidiaries);•difficulties and costs of staffing and managing foreign operations;•the uncertainty and limitation of protection for intellectual property rights in some countries;•costs of compliance with foreign laws and regulations and the risks and costs of non-compliance with such laws and regulations;•costs of complying with U.S. laws and regulations for foreign operations, including the Foreign Corrupt Practices Act, import and exportcontrol laws, tariffs, trade barriers, economic sanctions and other regulatory or contractual limitations on our ability to sell our solutions incertain foreign markets, and the risks and costs of non-compliance;•heightened risks of unfair or corrupt business practices in certain geographies and of improper or fraudulent sales arrangements that mayimpact financial results and result in restatements of, and irregularities in, financial statements;•the potential for political unrest, acts of terrorism, hostilities or war;•management communication and integration problems resulting from cultural differences and geographic dispersion; and•multiple and possibly overlapping tax structures.Our business, including the sales of subscriptions of our solutions, may be subject to foreign governmental regulations, which varysubstantially from country to country and change from time to time. Failure to comply with these regulations could adversely affect our business.Further, in many foreign countries it is common for others to engage in business practices that are prohibited by our internal policies andprocedures or U.S. regulations applicable to us. Although we have implemented policies and procedures designed to ensure compliance with theselaws and policies, there can be no assurance that all of our employees, contractors, channel partners and agents have complied or will complywith these laws and policies. Violations of laws or key control policies by our employees, contractors, channel partners or agents could result indelays in revenue recognition, financial reporting misstatements, fines, penalties or the prohibition of the importation or exportation of our solutionsand could have a material adverse effect on our business and results of operations. If we are unable to successfully manage the challenges ofinternational operations, our business and operating results could be adversely affected.In addition, as of December 31, 2018, approximately 65% of our employees were located outside of the United States, and 54% of ouremployees were located in Pune, India. Accordingly, we are exposed to changes in laws governing our employee relationships in various U.S. andforeign jurisdictions, including laws and regulations regarding wage and hour requirements, fair labor standards, employee data privacy,unemployment tax rates, workers’ compensation rates, citizenship requirements and payroll and other taxes which may have a direct impact onour operating costs. We may continue to expand our international operations and international sales and marketing activities. Expansion ininternational markets has required, and will continue to require, significant management attention and resources. We may be unable to scale ourinfrastructure effectively or as quickly as our competitors in these markets and our revenues may not increase to offset any increased costs andoperating expenses, which would cause our results to suffer.Disruptive technologies could gain wide adoption and supplant our cloud security and compliance solutions, thereby weakening oursales and harming our results of operations.The introduction of products and services embodying new technologies could render our existing solutions obsolete or less attractive tocustomers. Our business could be harmed if new security and compliance technologies25 Table of Contentsare widely adopted. We may not be able to successfully anticipate or adapt to changing technology or customer requirements on a timely basis, orat all. If we fail to keep up with technological changes or to convince our customers and potential customers of the value of our solutions even inlight of new technologies, our business could be harmed and our revenues may decline.Our business and operations have experienced significant growth, and if we do not appropriately manage any future growth, or areunable to improve our systems and processes, our operating results may be negatively affected.We have experienced significant growth over the last several years. From 2016 to 2018, our revenues grew from $197.9 million to $278.9million, and our headcount increased from 510 employees at the beginning of 2016 to 1,194 employees as of December 31, 2018. We rely oninformation technology systems to help manage critical functions such as order processing, revenue recognition and financial forecasts. Tomanage any future growth effectively we must continue to improve and expand our IT systems, financial infrastructure, and operating andadministrative systems and controls, and continue to manage headcount, capital and processes in an efficient manner. We may not be able tosuccessfully implement improvements to these systems and processes in a timely or efficient manner.Our failure to improve our systems and processes, or their failure to operate in the intended manner, may result in our inability to manage thegrowth of our business and to accurately forecast our revenues, expenses and earnings, or to prevent certain losses. In addition, as we continueto grow, our productivity and the quality of our solutions may also be adversely affected if we do not integrate and train our new employees quicklyand effectively. Any future growth would add complexity to our organization and require effective coordination across our organization. Failure tomanage any future growth effectively could result in increased costs, harm our results of operations and lead to investors losing confidence in ourinternal systems and processes.Forecasts of market growth may prove to be inaccurate, and even if the markets in which we compete achieve the forecasted growth,there can be no assurance that our business will grow at similar rates, or at all.Growth forecasts relating to the expected growth in the market for IT security and compliance and other markets are subject to significantuncertainty and are based on assumptions and estimates which may prove to be inaccurate. Even if these markets experience the forecastedgrowth, we may not grow our business at similar rates, or at all. Our growth is subject to many factors, including our success in implementing ourbusiness strategy, which is subject to many risks and uncertainties. Accordingly, forecasts of market growth should not be taken as indicative ofour future growth.We rely on third-party channel partners to generate a substantial amount of our revenues, and if we fail to expand and manage ourdistribution channels, our revenues could decline and our growth prospects could suffer.Our success significantly depends upon establishing and maintaining relationships with a variety of channel partners and we anticipate thatwe will continue to depend on these partners in order to grow our business. For the years ended December 31, 2018, 2017 and 2016, we derivedapproximately 41%, 41% and 42%, respectively, of our revenues from sales of subscriptions for our solutions through channel partners, and thepercentage of revenues derived from channel partners may increase in future periods. Our agreements with our channel partners are generally non-exclusive and do not prohibit them from working with our competitors or offering competing solutions, and many of our channel partners have moreestablished relationships with our competitors. If our channel partners choose to place greater emphasis on products of their own or those offeredby our competitors, do not effectively market and sell our solutions, or fail to meet the needs of our customers, then our ability to grow ourbusiness and sell our solutions may be adversely affected. In addition, the loss of one or more of our larger channel partners, who may ceasemarketing our solutions with limited or no notice, and our possible inability to replace them, could adversely affect our sales. Moreover, our abilityto expand our distribution channels depends in part on our ability to educate our channel partners about our solutions, which can be complex. Ourfailure to recruit additional channel partners, or any reduction or delay in their sales of our solutions or conflicts between channel sales and ourdirect sales and marketing activities may harm our results of operations. Even if we are successful, these relationships may not result in greatercustomer usage of our solutions or increased revenues.In addition, the financial health of our channel partners and our continuing relationships with them are important to our success. Some ofthese channel partners may be unable to withstand adverse changes in economic conditions,26 Table of Contentswhich could result in insolvency and/or the inability of such distributors to obtain credit to finance purchases of our products and services. Inaddition, weakness in the end-user market could negatively affect the cash flows of our channel partners who could, in turn, delay paying theirobligations to us, which would increase our credit risk exposure. Our business could be harmed if the financial condition of some of these channelpartners substantially weakened and we were unable to timely secure replacement channel partners.Our solutions contain third-party open source software components, and our failure to comply with the terms of the underlying opensource software licenses could restrict our ability to sell our solutions.Our solutions contain software licensed to us by third-parties under so-called “open source” licenses, including the GNU General PublicLicense, the GNU Lesser General Public License, the BSD License, the Apache License and others. From time to time, there have been claimsagainst companies that distribute or use open source software in their products and services, asserting that such open source software infringesthe claimants’ intellectual property rights. We could be subject to suits by parties claiming that what we believe to be licensed open sourcesoftware infringes their intellectual property rights. Use and distribution of open source software may entail greater risks than use of third-partycommercial software, as open source licensors generally do not provide warranties or other contractual protections regarding infringement claimsor the quality of the code. In addition, certain open source licenses require that source code for software programs that are subject to the licensebe made available to the public and that any modifications or derivative works to such open source software continue to be licensed under thesame terms. If we combine our proprietary software with open source software in certain ways, we could, in some circumstances, be required torelease the source code of our proprietary software to the public. Disclosing the source code of our proprietary software could make it easier forcyber attackers and other third parties to discover vulnerabilities in or to defeat the protections of our solutions, which could result in our solutionsfailing to provide our customers with the security they expect from our services. This could harm our business and reputation. Disclosing ourproprietary source code also could allow our competitors to create similar products with lower development effort and time and ultimately couldresult in a loss of sales for us. Any of these events could have a material adverse effect on our business, operating results and financial condition.Although we monitor our use of open source software in an effort both to comply with the terms of the applicable open source licenses and toavoid subjecting our solutions to conditions we do not intend, the terms of many open source licenses have not been interpreted by U.S. courts,and there is a risk that these licenses could be construed in a way that could impose unanticipated conditions or restrictions on our ability tocommercialize our solutions. In this event, we could be required to seek licenses from third parties to continue offering our solutions, to make ourproprietary code generally available in source code form, to re-engineer our solutions or to discontinue the sale of our solutions if re-engineeringcould not be accomplished on a timely basis, any of which could adversely affect our business, operating results and financial condition.We rely on software-as-a-service vendors to operate certain functions of our business and any failure of such vendors to provide servicesto us could adversely impact our business and operations.We rely on third-party software-as-a-service vendors to operate certain critical functions of our business, including financial management andhuman resource management. If these services become unavailable due to extended outages or interruptions or because they are no longeravailable on commercially reasonable terms or prices, our expenses could increase, our ability to manage our finances could be interrupted andour processes for managing sales of our solutions and supporting our customers could be impaired until equivalent services, if available, areidentified, obtained and integrated, all of which could harm our business.We use third-party software and data that may be difficult to replace or cause errors or failures of our solutions that could lead to lostcustomers or harm to our reputation and our operating results.We license third-party software as well as security and compliance data from various third parties to deliver our solutions. In the future, thissoftware or data may not be available to us on commercially reasonable terms, or at all. Any loss of the right to use any of this software or datacould result in delays in the provisioning of our solutions until equivalent technology or data is either developed by us, or, if available, is identified,obtained and integrated, which could harm our business. In addition, any errors or defects in or failures of this third-party software or data couldresult in errors or defects in our solutions or cause our solutions to fail, which could harm our business and be costly to correct. Many of theseproviders attempt to impose limitations on their liability for such errors, defects or failures, and if enforceable, we may have additional liability toour customers or third-party providers that could harm our reputation and increase our operating costs.27 Table of ContentsWe will need to maintain our relationships with third-party software and data providers, and to obtain software and data from such providersthat do not contain any errors or defects. Any failure to do so could adversely impact our ability to deliver effective solutions to our customers andcould harm our operating results.Delays or interruptions in the manufacturing and delivery of our physical scanner appliances by our sole source manufacturer may harmour business.Upon customer request, we provide physical or virtual scanner appliances on a subscription basis as an additional capability to thecustomer’s subscription for use during their subscription term. Our physical scanner appliances are built by a single manufacturer. Our reliance ona sole manufacturer involves several risks, including a potential inability to obtain an adequate supply of physical scanner appliances and limitedcontrol over pricing, quality and timely deployment of such scanner appliances. In addition, replacing this manufacturer may be difficult and couldresult in an inability or delay in deploying our solutions to customers that request physical scanner appliances as part of their subscriptions.Furthermore, our manufacturer’s ability to timely manufacture and ship our physical scanner appliances depends on a variety of factors, suchas the availability of hardware components, supply shortages or contractual restrictions. In the event of an interruption from this manufacturer, wemay not be able to develop alternate or secondary sources in a timely manner. If we are unable to purchase physical scanner appliances inquantities sufficient to meet our requirements on a timely basis, we may not be able to effectively deploy our solutions to new customers thatrequest physical scanner appliances, which could harm our business.We are exposed to fluctuations in currency exchange rates, which could negatively affect our financial condition and results ofoperations.Our reporting currency is the U.S. dollar and we generate a majority of our revenues in U.S. dollars. However, for the year ended December31, 2018, we incurred approximately 24% of our expenses outside of the United States in foreign currencies, primarily Euros, British Pounds, andIndian Rupee, principally with respect to salaries and related personnel expenses associated with our European and Indian operations. Additionally,for the year ended December 31, 2018, approximately 19% of our revenues were generated in foreign currencies. Accordingly, changes inexchange rates may have a material adverse effect on our business, operating results and financial condition. The exchange rate between theU.S. dollar and foreign currencies has fluctuated substantially in recent years and may continue to fluctuate substantially in the future. We expectthat a majority of our revenues will continue to be generated in U.S. dollars for the foreseeable future and that a significant portion of our expenses,including personnel costs, as well as capital and operating expenditures, will continue to be denominated in the Euro, British Pound and IndianRupee. The results of our operations may be adversely affected by foreign exchange fluctuations.Derivative financial instruments are utilized by the Company to reduce foreign currency exchange risks. The Company uses foreign currencyforward contracts to mitigate the impact of foreign currency fluctuations of certain non-U.S. dollar denominated asset positions, to date primarilycash and accounts receivable (non-designated), as well as to manage foreign currency fluctuation risk related to forecasted transactions(designated). The Company accounts for these instruments as either non-designated or cash flow hedges, respectively.Failure to protect our proprietary technology and intellectual property rights could substantially harm our business and operatingresults.The success of our business depends in part on our ability to protect and enforce our trade secrets, trademarks, copyrights, patents andother intellectual property rights. We attempt to protect our intellectual property under copyright, trade secret, patent and trademark laws, andthrough a combination of confidentiality procedures, contractual provisions and other methods, all of which offer only limited protection.We primarily rely on our unpatented proprietary technology and trade secrets. Despite our efforts to protect our proprietary technology andtrade secrets, unauthorized parties may attempt to misappropriate, reverse engineer or otherwise obtain and use them. The contractual provisionsthat we enter into with employees, consultants, partners, vendors and customers may not prevent unauthorized use or disclosure of our proprietarytechnology or intellectual property rights and may not provide an adequate remedy in the event of unauthorized use or disclosure of our proprietarytechnology or intellectual property rights. Moreover, policing unauthorized use of our technologies, solutions and intellectual property is difficult,expensive and time-consuming, particularly in foreign countries where the laws28 Table of Contentsmay not be as protective of intellectual property rights as those in the United States and where mechanisms for enforcement of intellectualproperty rights may be weak. We may be unable to determine the extent of any unauthorized use or infringement of our solutions, technologies orintellectual property rights.As of December 31, 2018, we had sixteen issued patents and several pending U.S. patent applications, and we may file additional patentapplications in the future. Additionally, we have an exclusive license to four third-party patents. The process of obtaining patent protection isexpensive and time-consuming, and we may not be able to prosecute all necessary or desirable patent applications at a reasonable cost or in atimely manner, if at all. We may choose not to seek patent protection for certain innovations and may choose not to pursue patent protection incertain jurisdictions.Furthermore, it is possible that our patent applications may not result in granted patents, that the scope of our issued patents will be limited ornot provide the coverage originally sought, that our issued patents will not provide us with any competitive advantages, or that our patents andother intellectual property rights may be challenged by others or invalidated through administrative processes or litigation. In addition, issuance ofa patent does not guarantee that we have an absolute right to practice the patented invention. As a result, we may not be able to obtain adequatepatent protection or to enforce our issued patents effectively.From time to time, legal action by us may be necessary to enforce our patents and other intellectual property rights, to protect our tradesecrets, to determine the validity and scope of the intellectual property rights of others or to defend against claims of infringement or invalidity.Such litigation could result in substantial costs and diversion of resources and could negatively affect our business, operating results and financialcondition. If we are unable to protect our intellectual property rights, we may find ourselves at a competitive disadvantage to others who need notincur the additional expense, time and effort required to create the innovative solutions that have enabled us to be successful to date.Assertions by third parties of infringement or other violations by us of their intellectual property rights could result in significant costsand harm our business and operating results.Patent and other intellectual property disputes are common in our industry. Some companies, including some of our competitors, own largenumbers of patents, copyrights and trademarks, which they may use to assert claims against us. Third parties may in the future assert claims ofinfringement, misappropriation or other violations of intellectual property rights against us. They may also assert such claims against ourcustomers or channel partners whom we typically indemnify against claims that our solutions infringe, misappropriate or otherwise violate theintellectual property rights of third parties. As the numbers of products and competitors in our market increase and overlaps occur, claims ofinfringement, misappropriation and other violations of intellectual property rights may increase. Any claim of infringement, misappropriation or otherviolation of intellectual property rights by a third party, even those without merit, could cause us to incur substantial costs defending against theclaim and could distract our management from our business.The patent portfolios of our most significant competitors are larger than ours. This disparity may increase the risk that they may sue us forpatent infringement and may limit our ability to counterclaim for patent infringement or settle through patent cross-licenses. In addition, futureassertions of patent rights by third parties, and any resulting litigation, may involve patent holding companies or other adverse patent owners whohave no relevant product revenues and against whom our own patents may therefore provide little or no deterrence or protection. There can be noassurance that we will not be found to infringe or otherwise violate any third-party intellectual property rights or to have done so in the past.An adverse outcome of a dispute may require us to:•pay substantial damages, including treble damages, if we are found to have willfully infringed a third party’s patents or copyrights;•cease making, licensing or using solutions that are alleged to infringe or misappropriate the intellectual property of others;•expend additional development resources to attempt to redesign our solutions or otherwise develop non-infringing technology, which maynot be successful;•enter into potentially unfavorable royalty or license agreements in order to obtain the right to use necessary technologies or intellectualproperty rights; and29 Table of Contents•indemnify our partners and other third parties.In addition, royalty or licensing agreements, if required or desirable, may be unavailable on terms acceptable to us, or at all, and may requiresignificant royalty payments and other expenditures. Some licenses may also be non-exclusive, and therefore our competitors may have accessto the same technology licensed to us. Any of the foregoing events could seriously harm our business, financial condition and results ofoperations.If we are required to collect sales and use or other taxes on the solutions we sell, we may be subject to liability for past sales and ourfuture sales may decrease.Taxing jurisdictions, including state and local entities, have differing rules and regulations governing sales and use or other taxes, and theserules and regulations are subject to varying interpretations that may change over time. In particular, the applicability of sales taxes to oursubscription services in various jurisdictions is unclear. It is possible that we could face sales tax audits and that our liability for these taxes couldexceed our estimates as tax authorities could still assert that we are obligated to collect additional amounts as taxes from our customers andremit those taxes to those authorities. We could also be subject to audits with respect to state and international jurisdictions for which we have notaccrued tax liabilities. A successful assertion that we should be collecting additional sales or other taxes on our services in jurisdictions where wehave not historically done so and do not accrue for sales taxes could result in substantial tax liabilities for past sales, discourage customers frompurchasing our solutions or otherwise harm our business and operating results.We depend on the continued services and performance of our senior management and other key employees, the loss of any of whomcould adversely affect our business, operating results and financial condition.Our future performance depends on the continued services and continuing contributions of our senior management, particularly Philippe F.Courtot, our Chairman, President and Chief Executive Officer, and other key employees to execute on our business plan and to identify andpursue new opportunities and product innovations. We do not maintain key-man insurance for Mr. Courtot or for any other member of our seniormanagement team. From time to time, there may be changes in our senior management team resulting from the termination or departure ofexecutives. Our senior management and key employees are generally employed on an at-will basis, which means that they could terminate theiremployment with us at any time. The loss of the services of our senior management, particularly Mr. Courtot, or other key employees for anyreason could significantly delay or prevent the achievement of our development and strategic objectives and harm our business, financial conditionand results of operations.If we are unable to hire, retain and motivate qualified personnel, our business may suffer.Our future success depends, in part, on our ability to continue to attract and retain highly skilled personnel. The loss of the services of any ofour key personnel, the inability to attract or retain qualified personnel or delays in hiring required personnel, particularly in engineering and sales,may seriously harm our business, financial condition and results of operations. Any of our employees may terminate their employment at any time.Competition for highly skilled personnel is frequently intense, especially in the San Francisco Bay Area and Pune, India, locations in which wehave a substantial presence and need for highly skilled personnel and we may not be able to compete for these employees.We are required under accounting principles generally accepted in the United States (“U.S. GAAP”) to recognize compensation expense inour operating results for employee stock-based compensation under our equity grant programs, which may negatively impact our operating resultsand may increase the pressure to limit stock-based compensation that we might otherwise offer to current or potential employees, therebypotentially harming our ability to attract or retain highly skilled personnel. In addition, to the extent we hire personnel from competitors, we may besubject to allegations that they have been improperly solicited or divulged proprietary or other confidential information, which could result in adiversion of management's time and our resources.Changes in laws or regulations related to the Internet may diminish the demand for our solutions and could have a negative impact onour business.We deliver our solutions through the Internet. Federal, state or foreign government bodies or agencies have in the past adopted, and may inthe future adopt, laws or regulations affecting data privacy and the use of the Internet. In addition, government agencies or private organizationsmay begin to impose taxes, fees or other charges for accessing the Internet or on commerce conducted via the Internet. These laws or chargescould limit the viability of Internet-based solutions such as ours and reduce the demand for our solutions.30 Table of ContentsA portion of our revenues are generated by sales to government entities, which are subject to a number of challenges and risks.Government entities have historically been particularly concerned about adopting cloud-based solutions for their operations, including securitysolutions, and increasing sales of subscriptions for our solutions to government entities may be more challenging than selling to commercialorganizations. Selling to government entities can be highly competitive, expensive and time-consuming, often requiring significant upfront time andexpense without any assurance that we will win a sale. We have invested in the creation of a cloud offering certified under the Federal InformationSecurity Management Act, or FISMA, for government usage but we cannot be sure that we will continue to sustain or renew this certification, thatthe government will continue to mandate such certification or that other government agencies or entities will use this cloud offering. Governmentdemand and payment for our solutions may be impacted by public sector budgetary cycles and funding authorizations, with funding reductions ordelays adversely affecting public sector demand for our solutions. Government entities may have contractual or other legal rights to terminatecontracts with our channel partners for convenience or due to a default, and any such termination may adversely impact our future results ofoperations. Governments routinely investigate and audit government contractors’ administrative processes, and any unfavorable audit could resultin the government refusing to continue buying our solutions, a reduction of revenues or fines or civil or criminal liability if the audit uncoversimproper or illegal activities. Any such penalties could adversely impact our results of operations in a material way.Governmental export or import controls could subject us to liability if we violate them or limit our ability to compete in foreign markets.Our solutions are subject to U.S. export controls, specifically, the Export Administration Regulations and economic sanctions enforced by theOffice of Foreign Assets Control. We incorporate encryption technology into certain of our solutions. These encryption solutions and the underlyingtechnology may be exported only with the required export authorizations, including by license, a license exception or other appropriate governmentauthorizations. U.S. export controls may require submission of an encryption registration, product classification and/or annual or semi-annualreports. Governmental regulation of encryption technology and regulation of imports or exports of encryption products, or our failure to obtainrequired import or export authorization for our solutions, when applicable, could harm our international sales and adversely affect our revenues.Compliance with applicable regulatory requirements regarding the export of our solutions, including with respect to new releases of our solutions,may create delays in the introduction of our solutions in international markets, prevent our customers with international operations from deployingour solutions throughout their globally-distributed systems or, in some cases, prevent the export of our solutions to some countries altogether. Inaddition, various countries regulate the import of our appliance-based solutions and have enacted laws that could limit our ability to distributesolutions or could limit our customers’ ability to implement our solutions in those countries. Any new export or import restrictions, new legislationor shifting approaches in the enforcement or scope of existing regulations, or in the countries, persons or technologies targeted by suchregulations, could result in decreased use of our solutions by existing customers with international operations, declining adoption of our solutionsby new customers with international operations and decreased revenues. If we fail to comply with export and import regulations, we may be finedor other penalties could be imposed, including a denial of certain export privileges.Our success in acquiring and integrating other businesses, products or technologies could impact our financial position.In order to remain competitive, we have in the past and may in the future seek to acquire additional businesses, products, services ortechnologies. For example, we acquired 1Mobility on April 1, 2018 and Layered Insight on October 16, 2018. The environment for acquisitions inour industry is very competitive and acquisition candidate purchase prices may exceed what we would prefer to pay. Moreover, achieving theanticipated benefits of future acquisitions will depend in part upon whether we can integrate acquired operations, products and technology in atimely and cost-effective manner, and even if we achieve benefits from acquisitions, such acquisitions may still be viewed negatively bycustomers, financial markets or investors. The acquisition and integration process is complex, expensive and time-consuming, and may cause aninterruption of, or loss of momentum in, product development and sales activities and operations of both companies, as well as divert the attentionof management, and we may incur substantial cost and expense. We may issue equity securities which could dilute current stockholders’ownership, incur debt, assume contingent or other liabilities and expend cash in acquisitions, which could negatively impact our financial position,stockholder equity and stock price. We may not find suitable acquisition candidates, and acquisitions we complete may be unsuccessful. If weconsummate a transaction, we may be unable to integrate and manage31 Table of Contentsacquired products and businesses effectively or retain key personnel. If we are unable to effectively execute acquisitions, our business, financialcondition and operating results could be adversely affected.Our financial results are based in part on our estimates or judgments relating to our critical accounting policies. These estimates orjudgments may prove to be incorrect, which could harm our operating results and result in a decline in our stock price.The preparation of financial statements in conformity with U.S. GAAP requires management to make estimates and assumptions that affectthe amounts reported in the consolidated financial statements and accompanying notes. We base our estimates on historical experience and onvarious other assumptions that we believe to be reasonable under the circumstances, as provided in the section titled “Part II, Item 7 -Management’s Discussion and Analysis of Financial Condition and Results of Operations,” the results of which form the basis for makingjudgments about the carrying values of assets, liabilities, equity, revenues and expenses that are not readily apparent from other sources. Ouroperating results may be adversely affected if our assumptions change or if actual circumstances differ from those in our assumptions, whichcould cause our operating results to fall below the expectations of securities analysts and investors, resulting in a decline in our stock price.Significant assumptions and estimates used in preparing our consolidated financial statements include those related to revenue recognition,accounting for income taxes, stock-based compensation, and fair value measurement.Changes in financial accounting standards may cause adverse and unexpected revenue fluctuations and impact our reported results ofoperations.We prepare our financial statements in accordance with U.S. GAAP. These principles are subject to interpretation by the SEC and variousbodies formed to interpret and create appropriate accounting principles. A change in these accounting standards or practices could harm ouroperating results and could have a significant effect on our reporting of transactions and reported results and may even retroactively affectpreviously reported transactions. New accounting pronouncements and varying interpretations of accounting pronouncements have occurred andmay occur in the future. Changes to existing rules or the questioning of current practices may harm our operating results or require that we makesignificant changes to our systems, processes and controls or the way we conduct our business.We have historically expensed commissions associated with sales of our solutions immediately upon receipt of a subscription orderfrom a customer and generally recognize the revenues associated with such sale over the term of the agreement. Accordingly, ourhistorical operating income in any period may not be indicative of our financial health and future performance. With the adoption ofAccounting Standards Codification (ASC) 606, Revenue from Contracts with Customers effective January 1, 2018, we commencedcapitalizing our commissions but elected to use the practical expedient in ASC 606 and expense commissions related to contracts with arenewal contract term of one year or less. As a result of the adoption of ASC 606, our future operating results may vary from period toperiod as our commission expense will not be directly comparable to historical periods.Through December 2017, we expensed commissions paid to our sales personnel in the quarter in which the related order was received. Incontrast, we have generally recognized the revenues associated with a sale of our solutions ratably over the term of the subscription, which istypically one year. Accordingly, our historical results may have fluctuated based on timing of commission expenses as compared to revenuerecognized. With the adoption of ASC 606, our operating results will also fluctuate and not be comparable to historical periods and will continue tofluctuate as we will generally capitalize commissions for new and upsell contracts except for renewal sales that are one year or less. In addition,amortization of expense from previously capitalized contracts is expected to increase over time as our opening capitalized commission assetbalance upon adoption of ASC 606 only included open contracts as of December 31, 2017. Accordingly, we expect our commission expense togrow in future periods as a result of the adoption of ASC 606. Without the adoption of ASC 606, commission expenses would have been $2.5million higher for the year ended December 31, 2018.We recognize revenues from subscriptions over the term of the relevant service period, and therefore any decreases or increases inbookings are not immediately reflected in our operating results.We recognize revenues from subscriptions over the term of the relevant service period, which is typically one year. As a result, most of ourreported revenues in each quarter are derived from the recognition of deferred revenues relating to subscriptions entered into during previousquarters. Consequently, a shortfall in demand for our solutions in any period may not significantly reduce our revenues for that period, but couldnegatively affect revenues in future32 Table of Contentsperiods. Accordingly, the effect of significant downturns in bookings may not be fully reflected in our results of operations until future periods. Wemay be unable to adjust our costs and expenses to compensate for such a potential shortfall in revenues. Our subscription model also makes itdifficult for us to rapidly increase our revenues through additional bookings in any period, as revenues are recognized ratably over the subscriptionperiod.Changes in our provision for income taxes or adverse outcomes resulting from examination of our income tax returns could adverselyaffect our operating results. We could be subject to additional taxes.We are subject to income taxes in the United States and various foreign jurisdictions, and our domestic and international tax liabilities aresubject to the allocation of expenses in differing jurisdictions. Our tax rate is affected by changes in the mix of earnings and losses in countrieswith differing statutory tax rates, certain non-deductible expenses arising from the requirement to expense stock options, excess tax benefits fromstock-based compensation, and the valuation of deferred tax assets and liabilities, including our ability to utilize our federal and state net operatinglosses, which were $62.4 million as of December 31, 2018. As a result of the Tax Cuts and Jobs Act (“the 2017 Tax Act”), which was enacted bythe U.S. federal government on December 22, 2017, our federal tax rate decreased in 2018. Accordingly, our operating results have fluctuated andmay not be comparable to historical periods and may continue to fluctuate in the future. Increases in our effective tax rate could harm ouroperating results.Additionally, significant judgment is required in evaluating our tax positions and our worldwide provision for taxes. During the ordinary courseof business, there are many activities and transactions for which the ultimate tax determination is uncertain. In addition, our tax obligations andeffective tax rates could be adversely affected by changes in the relevant tax, accounting and other laws, regulations, principles andinterpretations, including those relating to income tax nexus, by recognizing tax losses or lower than anticipated earnings in jurisdictions where wehave lower statutory rates and higher than anticipated earnings in jurisdictions where we have higher statutory rates, by changes in foreigncurrency exchange rates, or by changes in the valuation of our deferred tax assets and liabilities. We may be audited in various jurisdictions, andsuch jurisdictions may assess additional taxes, sales taxes and value-added taxes against us. Although we believe our tax estimates arereasonable, the final determination of any tax audits or litigation could be materially different from our historical tax provisions and accruals, whichcould have a material adverse effect on our operating results or cash flows in the period or periods for which a determination is made.Uncertainties in the interpretation and application of the 2017 Tax Cuts and Jobs Act could materially affect our tax obligations andeffective tax rate. The 2017 Tax Act significantly affected U.S. tax law by changing how the U.S. imposes income tax on multinational corporations. OnDecember 22, 2017, Staff Accounting Bulletin No. 118 ("SAB 118") was issued to address the application of U.S. GAAP in situations when aregistrant does not have the necessary information available, prepared, or analyzed (including computations) in reasonable detail to complete theaccounting for certain income tax effects of the 2017 Tax Act. In accordance with SAB 118, the effects of the 2017 Tax Act may be adjustedwithin a one-year measurement period from the enactment date of the 2017 Tax Act for items that were previously reported as provisionalestimates, or where a provisional estimate could not be made. During 2018, we completed our analysis within the measurement period inaccordance with the SEC guidance. The final resolution of provisional amounts relating to the effects of the 2017 Tax Act did not have a materialimpact to our effective tax rate. However, the U.S. Treasury Department, the IRS, and other standard-setting bodies continue to interpret or issueguidance on how provisions of the 2017 Tax Act will be applied or otherwise administered. As future guidance is issued, it may have an adverseeffect on our business, financial condition, results of operations, or cash flows in the period such guidance is issued.Our business is subject to the risks of earthquakes, fire, power outages, floods and other catastrophic events, and to interruption byman-made problems such as terrorism.A significant natural disaster, such as an earthquake, fire or a flood, or a significant power outage could have a material adverse impact onour business, operating results and financial condition. Our corporate headquarters and a significant portion of our operations are located in theSan Francisco Bay Area, a region known for seismic activity. In addition, natural disasters could affect our business partners’ ability to performservices for us on a timely basis. In the event we or our business partners are hindered by any of the events discussed above, our ability toprovide our solutions to customers could be delayed, resulting in our missing financial targets, such as revenues and net income, for a particularquarter. Further, if a natural disaster occurs in a region from which we derive a significant portion of our revenues, customers in that region maydelay or forego subscriptions of our solutions, which may materially and adversely impact our results of operations for a particular period. Inaddition, acts of terrorism could33 Table of Contentscause disruptions in our business or the business of our business partners, customers or the economy as a whole. All of the aforementioned risksmay be exacerbated if the disaster recovery plans for us and our suppliers prove to be inadequate. To the extent that any of the above results indelays of customer subscriptions or commercialization of our solutions, our business, financial condition and results of operations could beadversely affected.If we fail to maintain an effective system of internal control over financial reporting, our ability to produce timely and accurate financialstatements or comply with applicable regulations could be impaired.As a public company, we are subject to the reporting requirements of the Securities Exchange Act of 1934, or the Exchange Act, theSarbanes-Oxley Act of 2002, or the Sarbanes-Oxley Act, and the rules and regulations of the NASDAQ Stock Market. To continue to comply withthe requirements of being a public company, we may need to undertake various actions, such as implementing additional internal controls andprocedures and hiring additional accounting or internal audit staff.Our internal control over financial reporting is a process designed to provide reasonable assurance regarding the reliability of financialreporting and the preparation of financial statements in accordance with GAAP. Our current controls and any new controls that we develop maybecome inadequate because of changes in conditions in our business. Any failure to maintain effective controls, or any difficulties encountered intheir improvement, could harm our operating results or cause us to fail to meet our reporting obligations. Any failure to maintain effective internalcontrol over financial reporting also could adversely affect the results of periodic management evaluations regarding the effectiveness of ourinternal control over financial reporting that we are required to include in our periodic reports we file with the SEC under Section 404 of theSarbanes-Oxley Act. While we were able to assert in this Annual Report on Form 10-K that our internal control over financial reporting waseffective as of December 31, 2018, we cannot predict the outcome of our testing in future periods. If we are unable to assert in any future reportingperiod that our internal control over financial reporting is effective (or if our independent registered public accounting firm is unable to express anopinion on the effectiveness of our internal controls), investors may lose confidence in our operating results and our stock price could decline. Inaddition, if we are unable to continue to meet these requirements, we may not be able to remain listed on the NASDAQ Stock Market.Market volatility may affect our stock price and the value of an investment in our common stock and could subject us to litigation.The trading price of our common stock has been, and may continue to be, subject to significant fluctuations in response to a number offactors, most of which we cannot predict or control, including:•announcements of new solutions, services or technologies, commercial relationships, acquisitions or other events by us or ourcompetitors;•fluctuations in stock market prices and trading volumes of securities of similar companies;•general market conditions and overall fluctuations in U.S. equity markets;•variations in our operating results, or the operating results of our competitors;•changes in our financial guidance or securities analysts’ estimates of our financial performance;•changes in accounting principles;•sales of large blocks of our common stock, including sales by our executive officers, directors and significant stockholders;•additions or departures of any of our key personnel;•announcements related to litigation;•changing legal or regulatory developments in the United States and other countries; and•discussion of us or our stock price by the financial press and in online investor communities.34 Table of ContentsIn addition, the stock market in general, and the stocks of technology companies such as ours in particular, have experienced substantialprice and volume volatility that is often seemingly unrelated to the operating performance of particular companies. These broad market fluctuationsmay cause the trading price of our common stock to decline. In the past, securities class action litigation has often been brought against acompany after a period of volatility in the trading price of its common stock. We may become involved in this type of litigation in the future. Anysecurities litigation claims brought against us could result in substantial expenses and the diversion of our management’s attention from ourbusiness.Our actual operating results may differ significantly from our guidance.From time to time, we have released, and may continue to release, guidance in our quarterly earnings conference calls, quarterly earningsreleases, or otherwise, regarding our future performance that represents our management's estimates as of the date of release. This guidance,which includes forward-looking statements, has been and will be based on projections prepared by our management. These projections are notprepared with a view toward compliance with published guidelines of the American Institute of Certified Public Accountants, and neither ourregistered public accountants nor any other independent expert or outside party compiles or examines the projections. Accordingly, no suchperson expresses any opinion or any other form of assurance with respect to the projections.Projections are based upon a number of assumptions and estimates that, while presented with numerical specificity, are inherently subject tosignificant business, economic and competitive uncertainties and contingencies, many of which are beyond our control and are based uponspecific assumptions with respect to future business decisions, some of which will change. We intend to state possible outcomes as high and lowranges which are intended to provide a sensitivity analysis as variables are changed but are not intended to imply that actual results could not falloutside of the suggested ranges. The principal reason that we release guidance is to provide a basis for our management to discuss our businessoutlook with analysts and investors. We do not accept any responsibility for any projections or reports published by any such third parties.Guidance is necessarily speculative in nature, and it can be expected that some or all of the assumptions underlying the guidance furnishedby us will not materialize or will vary significantly from actual results. Accordingly, our guidance is only an estimate of what management believesis realizable as of the date of release. Actual results may vary from our guidance and the variations may be material. In light of the foregoing,investors are urged not to rely upon our guidance in making an investment decision regarding our common stock.Any failure to successfully implement our operating strategy or the occurrence of any of the events or circumstances set forth in this “RiskFactors” section in this Annual Report on Form 10-K could result in our actual operating results being different from our guidance, and thedifferences may be adverse and material.Concentration of ownership among our existing executive officers, directors and holders of 10% or more of our outstanding commonstock may prevent new investors from influencing significant corporate decisions.As of December 31, 2018, our executive officers, directors and holders of 10% or more of our outstanding common stock beneficially owned,in the aggregate, approximately 27% of our outstanding common stock. As a result, such persons, acting together, have significant ability tocontrol our management and affairs and substantially all matters submitted to our stockholders for approval, including the election and removal ofdirectors and approval of any significant transaction. This concentration of ownership may have the effect of delaying, deferring or preventing achange in control, impeding a merger, consolidation, takeover or other business combination involving us, or discouraging a potential acquirer frommaking a tender offer or otherwise attempting to obtain control of our business, even if such a transaction would benefit other stockholders.Future sales of shares by existing stockholders could cause our stock price to decline.The market price of shares of our common stock could decline as a result of substantial sales of our common stock, particularly sales by ourdirectors, executive officers, employees and significant stockholders, a large number of shares of our common stock becoming available for sale,or the perception in the market that holders of a large number of shares intend to sell their shares. As of December 31, 2018, we hadapproximately 39.0 million shares of our common stock outstanding.35 Table of ContentsIn addition, as of December 31, 2018, there were approximately 1.2 million restricted stock units and options to purchase approximately 3.4million shares of our common stock outstanding. If such options are exercised and restricted stock units are released, these additional shares willbecome available for sale. As of December 31, 2018, we had an aggregate of 3.8 million shares of our common stock reserved for future issuanceunder our 2012 Equity Incentive Plan, which can be freely sold in the public market upon issuance. If a large number of these shares are sold inthe public market, the sales could reduce the trading price of our common stock.We cannot guarantee that our stock repurchase program will be fully consummated or that it will enhance stockholder value, and anystock repurchases we make could affect the price of our common stock.In February 2018, we announced a $100.0 million stock repurchase program and in October 2018, we announced an additional $100.0 millionstock repurchase program. Although our Board of Directors authorized this stock repurchase program, we are not obligated to repurchase anyspecific dollar amount or to acquire any specific number of shares. The stock repurchase program could affect the price of our common stock,increase volatility and diminish our cash reserves. In addition, it may be suspended or terminated at any time, which may result in a decrease inthe price of our common stock. In the year ended December 31, 2018, we repurchased 1,088,899 shares of our common stock for an aggregatepurchase price of approximately $85.0 million.We do not intend to pay dividends on our common stock and therefore any returns will be limited to the value of our stock.We have never declared or paid any cash dividend on our common stock. We currently anticipate that we will retain future earnings for thedevelopment, operation and expansion of our business and do not anticipate declaring or paying any cash dividends for the foreseeable future. Anyreturn to stockholders will therefore be limited to the value of their stock.Anti-takeover provisions in our charter documents and under Delaware law could make an acquisition of us, which may be beneficial toour stockholders, more difficult and may prevent attempts by our stockholders to replace or remove our current management.Our amended and restated certificate of incorporation and amended and restated bylaws contain provisions that may delay or prevent anacquisition of us or a change in our management. These provisions include:•authorizing “blank check” preferred stock, which could be issued by the board without stockholder approval and may contain voting,liquidation, dividend and other rights superior to our common stock, which would increase the number of outstanding shares and couldthwart a takeover attempt;•a classified board of directors whose members can only be dismissed for cause;•the prohibition on actions by written consent of our stockholders;•the limitation on who may call a special meeting of stockholders;•the establishment of advance notice requirements for nominations for election to our Board of Directors or for proposing matters that canbe acted upon at stockholder meetings; and•the requirement of at least two-thirds of the outstanding capital stock to amend any of the foregoing second through fifth provisions.In addition, because we are incorporated in Delaware, we are governed by the provisions of Section 203 of the Delaware General CorporationLaw, which limits the ability of stockholders owning in excess of 15% of our outstanding voting stock to merge or combine with us. Although webelieve these provisions collectively provide for an opportunity to obtain greater value for stockholders by requiring potential acquirers to negotiatewith our Board of Directors, they would apply even if an offer rejected by our board were considered beneficial by some stockholders. In addition,these provisions may frustrate or prevent any attempts by our stockholders to replace or remove our current management by making it moredifficult for stockholders to replace members of our Board of Directors, which is responsible for appointing the members of our management.Item 1B.Unresolved Staff Comments36 Table of ContentsNone.37 Table of ContentsItem 2.PropertiesOur principal executive offices are located in Foster City, California, where we occupy a 76,922 square-foot facility under a lease expiring onApril 30, 2028. We have additional U.S. offices in Bellevue, Washington and Raleigh, North Carolina. We also lease offices in Courbevoie, France;Moscow, Russia; Munich, Germany; Frankfurt, Germany; Nuremberg, Germany; Pune, India; Dubai, United Arab Emirates; Reading, UnitedKingdom; and Tokyo, Japan. We believe our facilities are adequate for our current needs and for the foreseeable future.We operate principal data centers at third-party facilities in Santa Clara, California; Ashburn, Virginia; Geneva, Switzerland; Pune, India; andAmsterdam, the Netherlands.Item 3.Legal ProceedingsFrom time to time we may become involved in legal proceedings or be subject to claims arising in the ordinary course of our business. Weare not presently a party to any legal proceedings that, if determined adversely to us, would individually or taken together have a material adverseeffect on our business, operating results, financial condition or cash flows. Regardless of the outcome, litigation can have an adverse impact on usbecause of defense and settlement costs, diversion of management resources and other factors.Item 4.Mine Safety Disclosures.Not Applicable.38 Table of ContentsPART IIItem 5.Market for Registrant's Common Equity, Related Stockholder Matters and Issuer Purchases ofEquity SecuritiesHolders of Common EquityAs of January 31, 2019, there were approximately 85 holders of record of our common stock. Because many of our shares of common stockare held by brokers and other institutions on behalf of stockholders, we are unable to estimate the total number of stockholders represented bythese record holders.Dividend PolicyWe have never declared or paid any cash dividends on our capital stock. We currently intend to retain any future earnings to fund businessdevelopment and growth, and do not expect to pay any dividends in the foreseeable future. Any future determination to declare cash dividends willbe made at the discretion of our Board of Directors, subject to applicable laws, and will depend on a number of factors, including our financialcondition, results of operations, capital requirements, contractual restrictions, general business conditions and other factors that our Board ofDirectors may deem relevant.Securities Authorized for Issuance under Equity Compensation PlansThe following table summarizes information about our equity compensation plans as of December 31, 2018. All outstanding awards relate toour common stock.Plan Category (a) Number of Securities to beIssued UponExercise ofOutstandingOptions, Warrantsand Rights (b) Weighted-AverageExercise Price ofOutstanding Options,Warrants and Rights (c) Number of SecuritiesRemaining Available forFuture Issuance UnderEquity CompensationPlans (ExcludingSecurities Reflected inColumn (a)Equity compensation plans approved bysecurity holders(1) 3,429,309 $31.8 3,817,097Equity compensation plans not approvedby security holders — $— —(1) Equity compensation plans approved by stockholders include the 2000 Equity Incentive Plan, as amended and the 2012 Equity IncentivePlan. Prior to our IPO, we issued securities under our 2000 Equity Incentive Plan, as amended. Following our IPO, we issued securities underour 2012 Equity Incentive Plan.39 Table of ContentsStock Price Performance GraphThe following graph shows a comparison from December 31, 2013 through December 31, 2018 of the cumulative total return for aninvestment of $100 (and the reinvestment of dividends) in our common stock, the NASDAQ Global Select Market and the NASDAQ Computer.Such returns are based on historical results and are not intended to suggest future performance.COMPARISON OF CUMULATIVE TOTAL RETURN*Among Qualys, Inc., NASDAQ-Global Select Market Composite Index, and NASDAQ Computer Index* $100 invested on 12/31/13 in stock or index, including reinvestment of dividends. Fiscal year ending December 31. Dec 31, 2013 Dec 31, 2014 Dec 31, 2015 Dec 31, 2016 Dec 31, 2017 Dec 31, 2018Qualys, Inc.$100.00 $163.35 $143.18 $136.95 $256.82 $323.41NASDAQ Global Select Market$100.00 $113.70 $120.64 $129.80 $166.71 $160.58NASDAQ Computer$100.00 $119.88 $127.36 $142.99 $198.42 $191.11The information on the above Stock Price Performance Graph shall not be deemed to be “filed” for purposes of Section 18 of the SecuritiesExchange Act of 1934, as amended, or otherwise subject to the liabilities of that section or Sections 11 and 12(a)(2) of the Securities Act of 1933,as amended, and shall not be incorporated by reference into any registration statement or other document filed by us with the Securities andExchange Commission, whether made before or after the date of this Annual Report on Form 10-K, regardless of any general incorporationlanguage in such filing, except as shall be expressly set forth by specific reference in such filing.Purchases of Equity Securities by the Issuer and Affiliated PurchasersOn February 5, 2018, our Board of Directors authorized a $100.0 million two-year share repurchase program, which was announced onFebruary 12, 2018. On October 25, 2018, the Company's Board of Directors authorized an additional $100.0 million two-year share repurchaseprogram, which was announced on October 30, 2018 and. Our share repurchases may be effected from time to time through open marketpurchases or pursuant to a Rule 10b5-1 plan. All share repurchases40 Table of Contentswere made using cash resources. As of December 31, 2018, approximately $115.0 million remained available for share repurchases pursuant toour share repurchase program.A summary of our repurchases of common stock during the fourth quarter of 2018 is as follows:Period Total Numberof SharesPurchased Average PricePaid per Share Total Number of SharesPurchased as Part ofPublicly Announced Planor Program Approximate DollarValue of Shares that MayYet Be Purchased underthe Plan or ProgramOctober 1, 2018 - October 31, 2018 — $— — $153,458,021November 1, 2018 - November 30, 2018 521,257 $73.86 521,257 $114,959,626December 1, 2018 - December 31, 2018 — $— — $114,959,626Total 521,257 521,257 41 Table of ContentsItem 6.Selected Consolidated Financial DataThe following selected consolidated financial data should be read in conjunction with "Item 7. Management’s Discussion and Analysis ofFinancial Condition and Results of Operations” and our consolidated financial statements, related notes and other financial information includedelsewhere in this Annual Report on Form 10-K. Our historical results are not necessarily indicative of the results that may be expected in thefuture, and the results for the year ended December 31, 2018 are not necessarily indicative of operating results to be expected for any otherperiod. As of December 31, 2018 2017 2016 2015 2014 (in thousands, except per share data)Consolidated Statements of Operations Data: Revenues $278,889 $230,828 $197,925 $164,284 $133,579Income from operations $50,361 $37,243 $30,107 $24,806 $9,247Net income $57,304 $40,440 $19,224 $15,865 $30,244Net income per share attributable to common stockholders: (1) Basic $1.47 $1.08 $0.55 $0.47 $0.92Diluted $1.37 $1.01 $0.50 $0.42 $0.81 As of December 31, 2018 2017 2016 2015 2014 (in thousands)Consolidated Balance Sheet Data: Cash, cash equivalents and short-term investments $289,166 $288,414 $243,856 $178,966 $127,218Long-term investments 76,710 67,224 45,725 43,277 39,448Total assets 585,680 537,525 407,004 323,514 260,024Deferred revenues, current 164,624 143,186 114,964 98,025 81,147Deferred revenues, noncurrent 20,423 17,136 15,528 14,564 10,064Total stockholders’ equity 357,989 343,544 258,413 195,566 151,827 (1) See Notes 1 and 12 to our consolidated financial statements included elsewhere in this Annual Report on Form 10-K for an explanation of the calculationof our basic and diluted income per share attributable to common stockholders.42 Table of ContentsItem 7.Management's Discussion and Analysis of Financial Condition and Results of OperationsYou should read the following discussion in conjunction with the section titled "Selected Consolidated Financial Data" and ourconsolidated financial statements and the related notes included elsewhere in this Annual Report on Form 10-K. In addition to historicalinformation, this discussion contains forward-looking statements that involve risks and uncertainties that could cause our actual results todiffer materially from our expectations, as discussed in "Forward-Looking Statements" in Part I of this Annual Report on Form 10-K. Factorsthat could cause such differences include, but are not limited to, those described in the section titled "Risk Factors" and elsewhere in thisAnnual Report on Form 10-K.OverviewWe are a pioneer and leading provider of a cloud-based platform delivering security and compliance solutions that enable organizations toidentify security risks to their information technology (IT) infrastructures, help protect their IT systems and applications from ever-evolvingcyber-attacks and achieve compliance with internal policies and external regulations. Our cloud solutions address the growing security andcompliance complexities and risks that are amplified by the dissolving boundaries between internal and external IT infrastructures and webenvironments, the rapid adoption of cloud computing, containers and serverless IT models, and the proliferation of geographically dispersed ITassets. Our integrated suite of security and compliance solutions delivered on our Qualys Cloud Platform enables our customers to identifyand manage their IT assets, collect and analyze large amounts of IT security data, discover and prioritize vulnerabilities, recommendremediation actions and verify the implementation of such actions. Organizations use our integrated suite of solutions delivered on our QualysCloud Platform to cost-effectively obtain a unified view of their IT asset inventory as well as security and compliance posture across globally-distributed IT infrastructures as our solution offers a single platform for information technology, information security, application security,endpoint, developer security and cloud teams.We were founded and incorporated in December 1999 with a vision of transforming the way organizations secure and protect their ITinfrastructure and applications and initially launched our first cloud solution, Vulnerability Management (VM), in 2000. As VM gainedacceptance, we introduced additional solutions to help customers manage increasing IT security and compliance requirements. Today, thesuite of solutions that we offer on our cloud platform and refer to as the Qualys Cloud Apps helps our customers protect a range of on-premiseassets, endpoints and cloud environments. These solutions and their Cloud Apps address and include:•IT Security: Vulnerability Management (VM), Threat Protection (TP), Continuous Monitoring (CM), Indicationof Compromise (IOC), Certificate Assessment (CRA);•Compliance Monitoring: Policy Compliance (PC), PCI Compliance (PCI), File Integrity Monitoring (FIM),Security Configuration Assessment (SCA), Security Assessment Questionnaire (SAQ); •Web Application Security: Web Application Scanning (WAS), Web Application Firewall (WAF);•Global IT Asset Management: Asset Inventory (AI), CMDB Sync (SYN), Certificate Inventory (CRI); and•Cloud/Container Security: Cloud Inventory (CI), Cloud Security Assessment (CSA), Container Security (CS).Our VM solutions (including VM, CM, TP, Cloud Agent for VM, allocated scanner revenue and Qualys Private Cloud Platform) haveprovided a substantial majority of our revenues to date, representing 74%, 74% and 76% of total revenues in 2018, 2017 and 2016,respectively.We provide our solutions through a software-as-a-service model, primarily with renewable annual subscriptions. These subscriptionsrequire customers to pay a fee in order to access each of our cloud solutions. We generally invoice our customers for the entire subscriptionamount at the start of the subscription term, and the invoiced amounts are treated as deferred revenues and are recognized ratably over theterm of each subscription. We continue to experience significant revenue growth from our existing customers as they renew and purchaseadditional subscriptions.43 Table of ContentsWe market and sell our solutions to enterprises, government entities and small and medium-sized businesses across a broad range ofindustries, including education, financial services, government, healthcare, insurance, manufacturing, media, retail, technology and utilities. Asof December 31, 2018, we had over 12,200 customers and active users in more than 130 countries, including a majority of each of the ForbesGlobal 100 and Fortune 100. In 2018, 2017 and 2016, approximately 67%, 70% and 71%, respectively, of our revenues were derived fromcustomers in the United States. We sell our solutions to enterprises and government entities primarily through our field sales force and tosmall and medium-sized businesses through our inside sales force. We generate a significant portion of sales through our channel partners,including managed service providers, value-added resellers and consulting firms in the United States and internationally.We have had continued revenue growth over the past three years. Our revenues increased from $197.9 million in 2016 to $230.8 million in2017, and reached $278.9 million in 2018, representing period-over-period increases of $32.9 million and $48.1 million in 2017 and 2018, or17% and 21%, respectively. We generated net income of $19.2 million in 2016, $40.4 million in 2017, and $57.3 million in 2018.Key MetricIn addition to measures of financial performance presented in our consolidated financial statements, we monitor the key metric set forthbelow to help us evaluate growth trends, establish budgets, measure the effectiveness of our sales and marketing efforts and assess operationalefficiencies. Year Ended December 31, 2018 2017 2016 (in thousands)Adjusted EBITDA $112,380 $84,933 $67,966Adjusted EBITDAWe monitor Adjusted EBITDA, a non-GAAP financial measure, to analyze our financial results and believe that it is useful to investors, as asupplement to U.S. GAAP measures, in evaluating our ongoing operational performance and enhancing an overall understanding of our pastfinancial performance. We believe that Adjusted EBITDA helps illustrate underlying trends in our business that could otherwise be masked by theeffect of the income or expenses that we exclude in Adjusted EBITDA. Furthermore, we use this measure to establish budgets and operationalgoals for managing our business and evaluating our performance. We also believe that Adjusted EBITDA provides an additional tool for investorsto use in comparing our recurring core business operating results over multiple periods with other companies in our industry.Adjusted EBITDA should not be considered in isolation from, or as a substitute for, financial information prepared in accordance with U.S.GAAP. We calculate Adjusted EBITDA as net income before (1) other (income) expense, net, which includes interest income, interest expenseand other income and expense, (2) provision for (benefit from) income taxes, (3) depreciation of property and equipment, (4) amortization ofintangible assets, (5) stock-based compensation, (6) non-recurring expenses and (7) cash acquisition-related expense that do not reflect ongoingcosts of operating the business.44 Table of ContentsThe following unaudited table presents the reconciliation of net income to Adjusted EBITDA for each of the periods presented. Year Ended December 31, 2018 2017 2016 (in thousands)Net income $57,304 $40,440 $19,224Depreciation of property and equipment 25,136 19,828 16,621Amortization of intangible assets 3,768 808 373Interest expense 172 3 26(Benefit from) provision for income taxes (1,836) (1,062) 11,205EBITDA 84,544 60,017 47,449Stock-based compensation 30,090 26,961 20,149Other income, net (5,279) (2,138) (348)Cash acquisition-related expense(1) 3,025 93 —One-time tax related expense(2) — — 716Adjusted EBITDA $112,380 $84,933 $67,966Percentage of revenues 40% 37% 34%(1) Relates to compensation expense from the acquisition of NetWatcher and Layered Insight.(2) Adjusted EBITDA for 2016 excludes approximately $0.7 million of a non-recurring expense related to the remittance of payroll taxes from fiscal year 2013 through May 2016.During this same period, we have not excluded any amounts related to other non-recurring items from Adjusted EBITDA because we have considered such amounts to beimmaterial.Limitations of Adjusted EBITDAAdjusted EBITDA, a non-GAAP financial measure, has limitations as an analytical tool, and should not be considered in isolation from or as asubstitute for the measures presented in accordance with U.S. GAAP. Some of these limitations are:•Adjusted EBITDA does not reflect certain cash and non-cash charges that are recurring;•Adjusted EBITDA does not reflect income tax payments that reduce cash available to us;•Adjusted EBITDA excludes depreciation of property and equipment and amortization of intangible assets, although these are non-cashcharges, the assets being depreciated and amortized may have to be replaced in the future; and•Other companies, including companies in our industry, may calculate Adjusted EBITDA differently or not at all, which reduces itsusefulness as a comparative measure.Because of these limitations, Adjusted EBITDA should be considered alongside other financial performance measures, including revenues,net income, cash flows from operating activities and our financial results presented in accordance with U.S. GAAP.Key Components of Results of OperationsRevenuesWe derive revenues from the sale of subscriptions to our security and compliance solutions, which are delivered on our cloud platform.Subscriptions to our solutions allow customers to access our cloud-based security and compliance solutions through a unified, web-basedinterface. Customers generally enter into one-year renewable subscriptions. The subscription fee entitles the customer to an unlimited number ofscans for a specified number of devices or web applications and, if requested by a customer as part of their subscription, a specified number ofphysical or virtual scanner appliances. Our physical and virtual scanner appliances are requested by certain customers as part of theirsubscriptions in order to scan IT infrastructures within their firewalls and do not function without, and are not sold separately from, subscriptions forour solutions. In some limited cases, we also provide certain computer equipment used to extend our Qualys Cloud Platform into our customers'private cloud environment. Customers are required to return physical scanner appliances and computer equipment if they do not renew theirsubscriptions.45 Table of ContentsWe typically invoice our customers for the entire subscription amount at the start of the subscription term. Invoiced amounts are reflected onour consolidated balance sheets as accounts receivable or as cash when collected, and as deferred revenues until earned and recognized ratablyover the subscription period. Accordingly, deferred revenues represent the amount billed to customers that has not yet been earned or recognizedas revenues, pursuant to subscriptions entered into in current and prior periods.Cost of RevenuesCost of revenues consists primarily of personnel expenses, comprised of salaries, benefits, amortization of internal-use software,performance-based compensation and stock-based compensation, for employees who operate our data centers and provide support services toour customers. Other expenses include depreciation of data center equipment and physical scanner appliances and computer hardware provided tocertain customers as part of their subscriptions, expenses related to the use of third-party data centers, amortization of third-party technologylicensing fees, amortization of intangibles related to acquisitions, maintenance support, fees paid to contractors who supplement or support ouroperations center personnel and overhead allocations. We expect to continue to make capital investments to expand and support our data centeroperations, which will increase the cost of revenues in absolute dollars.Operating ExpensesResearch and DevelopmentResearch and development expenses consist primarily of personnel expenses, comprised of salaries, benefits, performance-basedcompensation and stock-based compensation, for our research and development teams. Other expenses include third-party contractor fees,amortization of intangibles related to acquisitions and overhead allocations. All research and development costs are expensed as incurred, exceptfor capitalized costs related to new products' internal-use software development. Capitalized costs include salaries, benefits, and stock-basedcompensation charges for employees that are directly involved in developing its cloud security platform during the planning and postimplementation phases of development. Capitalized costs related to internally developed software under development are treated as constructionin progress until the program, feature or functionality is ready for its intended use, at which time amortization commences. We expect to continueto devote substantial resources to research and development in an effort to continuously improve our existing solutions as well as develop newsolutions and capabilities and expect that research and development expenses will increase in absolute dollars.Sales and MarketingSales and marketing expenses consist primarily of personnel expenses, comprised of salaries, benefits, sales commissions, performance-based compensation and stock-based compensation for our worldwide sales and marketing teams. Other expenses include marketing andpromotional events, lead-generation marketing programs, public relations, travel, software licenses and overhead allocations. Sales commissionscost related to new business and upsells are capitalized as an asset. We amortize the capitalized commission cost as a selling expense on astraight-line basis over a period of five years. We expense sales commissions related to contract renewals. Our new sales personnel are typicallynot immediately productive, and the resulting increase in sales and marketing expenses we incur when we add new personnel may not result inincreased revenues if these new sales personnel fail to become productive. The timing of our hiring of sales personnel, or the participation in newmarketing events or programs, and the rate at which these generate incremental revenues, may affect our future operating results. We expect tocontinue to significantly invest in additional sales personnel worldwide and also in more marketing programs to support new solutions on ourplatform, which will increase sales and marketing expenses in absolute dollars.General and AdministrativeGeneral and administrative expenses consist primarily of personnel expenses, comprised of salaries, benefits, performance-basedcompensation and stock-based compensation, for our executive, finance and accounting, legal and human resources teams, as well asprofessional services, insurance, fees, and software licenses. We expect that general and administrative expenses will increase in absolutedollars, as we continue to add personnel and incur professional services to support our growth and compliance with legal requirements.Other Income (Expense), Net46 Table of ContentsOur other income (expense), net consists primarily of interest and investment income from our short-term and long-term investments; foreignexchange gains and losses, the majority of which result from fluctuations between the U.S. dollar and the Euro, British Pound and Indian Rupee;losses on disposal of property and equipment; and impairment of long-lived assets.Provision for Income TaxesWe are subject to federal, state and foreign income taxes for jurisdictions in which we operate, and we use estimates in determining ourprovision for these income taxes and deferred tax assets. Earnings from our non-U.S. activities are subject to income taxes in the local countriesat rates which were generally similar to the U.S. statutory tax rate. Our effective rate differs from the U.S. statutory rate primarily due to excesstax benefits related to stock-based compensation, U.S. federal research and development tax credits, U.S. foreign tax credits, and non-deductiblecompensation to certain employees.Income taxes are accounted for under the asset and liability method. Deferred tax assets and liabilities are recognized for the tax impact oftiming differences between the financial statement carrying amounts of existing assets and liabilities and their respective tax bases and operatingloss and tax credit carry-forwards. Deferred tax assets and liabilities are measured using statutory tax rates expected to apply to taxable income inthe years in which those temporary differences are expected to be recovered or settled. The effect on deferred tax assets and liabilities of achange in tax rates is recognized in income in the period when the statutory rate change is enacted into law. During 2017, we recognized anexpense of $10.4 million as a result of re-measuring deferred tax assets and liabilities using the reduced U.S. federal tax rate of 21% whichdecreased from 35% due to the enactment of the 2017 Tax Act.We assess the likelihood that deferred tax assets will be realized, and we recognize a valuation allowance if it is more likely than not thatsome portion of the deferred tax assets will not be recognized. This assessment requires judgment as to the likelihood and amounts of futuretaxable income.Our benefit from income taxes in 2018 consists of a tax benefit from excess stock-based compensation deductions, as well as from U.S.federal research and development and foreign tax credits. The tax benefit was partially offset by a tax expense for non-deductible compensation ofcertain employees.Results of OperationsThe following tables set forth selected consolidated statements of operations data for each of the periods presented. Year Ended December 31, 2018 2017 2016 (in thousands)Consolidated Statements of Operations data: Revenues $278,889 $230,828 $197,925Cost of revenues (1) 66,185 51,580 43,128Gross profit 212,704 179,248 154,797Operating expenses: Research and development (1) 53,255 42,816 36,591Sales and marketing (1) 70,039 63,855 58,985General and administrative (1) 39,049 35,334 29,114Total operating expenses 162,343 142,005 124,690Income from operations 50,361 37,243 30,107Other income, net $5,107 $2,135 $322Income before income taxes 55,468 39,378 30,429(Benefit from) provision for income taxes (1,836) (1,062) 11,205Net income $57,304 $40,440 $19,224(1) Includes stock-based compensation as follows:47 Table of Contents Year Ended December 31, 2018 2017 2016 (in thousands)Cost of revenues $2,489 $2,159 $1,858Research and development 7,961 5,944 5,678Sales and marketing 4,650 4,755 4,870General and administrative 14,990 14,103 7,743Total stock-based compensation $30,090 $26,961 $20,14948 Table of ContentsThe following table sets forth selected consolidated statements of operations data for each of the periods presented as a percentage ofrevenues. Year Ended December 31, 2018 2017 2016Revenues 100 % 100 % 100%Cost of revenues 24 22 22Gross profit 76 78 78Operating expenses: Research and development 19 19 18Sales and marketing 25 28 30General and administrative 14 15 15Total operating expenses 58 62 63Income from operations 18 16 15Other income, net 2 1 0Income before income taxes 20 17 15(Benefit from) provision for income taxes (1) (1) 5Net income 21 % 18 % 10%Comparison of Years Ended December 31, 2018 and 2017Revenues Year Ended December 31, Change 2018 2017 $ % (in thousands, except percentages)Revenues $278,889 $230,828 $48,061 21%Revenues increased $48.1 million in 2018 compared to 2017 due to an increase in the subscriptions from existing customers and newcustomer subscriptions entered into in 2018. Revenues from customers existing at or prior to December 31, 2017 grew by $36.4 million to $267.2million during 2018. Subscriptions from new customers added in 2018 contributed $11.7 million to the increase in revenues. Of the total increase of$48.1 million, $23.2 million was from customers in the United States and the remaining $24.9 million was from customers in foreign countries. Weexpect revenue growth from existing and new customers to continue. The growth in revenues reflects the continued demand for our solutions.There was no impact to our revenues as a result of adopting Accounting Standards Codification ("ASC") 606. See in Part II, Item 8 of this AnnualReport on Form 10-K Note 4, “Revenue from Contracts with Customers”.Cost of Revenues Year Ended December 31, Change 2018 2017 $ % (in thousands, except percentages)Cost of revenues $66,185 $51,580 $14,605 28%Percentage of revenues 24% 22% Gross profit percentage 76% 78% Cost of revenues increased $14.6 million in 2018 compared to 2017, primarily due to an increase in personnel expenses of $4.5 million, drivenby additional employees hired to support the continued growth of our business; a $3.1 million increase in amortization expense related to acquiredtechnology resulting from our business acquisitions; a $2.6 million increase in depreciation expense related to additional computer hardware andsoftware; a $1.9 million increase in data center and supplies costs; an increase of $1.3 million in third-party software license49 Table of Contents& maintenance expense, resulting from our continued business growth; and $1.2 million increase related to other miscellaneous costs.Research and Development Expenses Year Ended December 31, Change 2018 2017 $ % (in thousands, except percentages)Research and development $53,255 $42,816 $10,439 24%Percentage of revenues 19% 19% Research and development expenses increased $10.4 million in 2018 compared to 2017, primarily due to an increase in personnel expensesof $8.5 million, driven by additional employees hired to support the growth of our business; an increase of $0.9 million in consulting & professionalservices costs; an increase of $0.8 million data center, third-party software license & maintenance expense; and a $1.5 million increase in othermiscellaneous costs; partially offset by software capitalization of $1.3 million. We continue to significantly invest in and expand our research anddevelopment teams to continuously improve our platform and existing solutions, as well as develop new solutions and capabilities.Sales and Marketing Expenses Year Ended December 31, Change 2018 2017 $ % (in thousands, except percentages)Sales and marketing $70,039 $63,855 $6,184 10%Percentage of revenues 25% 28% Sales and marketing expenses increased $6.2 million in 2018 compared to 2017, primarily due to an increase in personnel expenses of $2.9million, driven by additional employees hired to support the growth of our business; a $1.7 million increase in acquisition-related compensationexpense from Netwatcher; an increase of $1.6 million for trade shows; an increase of $1.2 million in recruiting, consulting and temporary services;an increase of $0.8 million in travel and entertainment expense and a $0.7 million increase in other miscellaneous costs. The increases werepartially offset by a decrease of $2.7 million in commission expense, primarily due to the adoption of ASC 606, resulting in us capitalizingcommissions on new business and upsells in the year ended December 31, 2018 versus expensing all commissions in the year ended December31, 2017.General and Administrative Expenses Year Ended December 31, Change 2018 2017 $ % (in thousands, except percentages)General and administrative $39,049 $35,334 $3,715 11%Percentage of revenues 14% 15% General and administrative expenses increased $3.7 million in 2018 compared to 2017, primarily driven by an increase of $1.8 million inconsulting, legal service fees and outside services; an increase of $1.2 million in personnel expenses; an increase of $0.3 million in taxes, fees &penalties, and $0.5 million increase related to other miscellaneous costs.50 Table of ContentsTotal Other Income, Net Year Ended December 31, Change 2018 2017 $ % (in thousands, except percentages)Total other income, net $5,107 $2,135 $2,972 139%Percentage of revenues 2% 1% Total other income, net, increased $3.0 million in 2018 compared to 2017, primarily due to the accretion of purchase discounts frommarketable securities balances increasing year over year.Benefit from Income Taxes Year Ended December 31, Change 2018 2017 $ % (in thousands, except percentages)Benefit from income taxes $1,836 $1,062 $774 73%Percentage of revenues 1% 1% We recorded an income tax benefit of $1.8 million in 2018 as compared to an income tax benefit of $1.1 million in 2017. This was primarilydue to an increase in our U.S. federal research and development and foreign tax credits. While the 2017 income tax benefit was driven by greaterexcess tax benefits from stock based compensation it was offset by $10.4 million of expense from the re-measuring of deferred tax assets andliabilities due to the decrease in the federal tax rate from 35% to 21% resulting from the Tax Cuts and Jobs Act, enacted into law on December 22,2017.Comparison of Years Ended December 31, 2017 and 2016Revenues Year Ended December 31, Change 2017 2016 $ % (in thousands, except percentages)Revenues $230,828 $197,925 $32,903 17%Revenues increased $32.9 million in 2017 compared to 2016. Revenues from customers existing at or prior to December 31, 2016 grew by$21.5 million to $219.4 million during 2017. Subscriptions from new customers added in 2017 contributed $11.4 million to the increase in revenues.Of the total increase of $32.9 million, $22.9 million was from customers in the United States and the remaining $10.0 million was from customersin foreign countries. The growth in revenues reflects the continued demand for our solutions. We expect revenue growth from existing and newcustomers to continue. The growth in revenues reflects the continued demand for our solutions.Cost of Revenues Year Ended December 31, Change 2017 2016 $ % (in thousands, except percentages)Cost of revenues $51,580 $43,128 $8,452 20%Percentage of revenues 22% 22% Gross profit percentage 78% 78% 51 Table of ContentsCost of revenues increased $8.5 million in 2017 compared to 2016, primarily due to an increase in personnel expenses of $4.1 million, drivenby the increase in the number of employees to support the continued growth of our business; a $2.8 million increase in depreciation expenserelated to additional computer hardware and software; a $0.5 million increase in amortization expense related to acquired technology resulting fromour business acquisitions; increased data center costs of $0.5 million; and increased consulting services and third-party software licensemaintenance expense of $0.2 million each as our business continues to grow.Research and Development Expenses Year Ended December 31, Change 2017 2016 $ % (in thousands, except percentages)Research and development $42,816 $36,591 $6,225 17%Percentage of revenues 19% 18% Research and development expenses increased $6.2 million in 2017 compared to 2016, primarily due to an increase in personnel expenses of$5.7 million, driven by additional employees hired to support the growth of our business; and increased related facilities costs and expenses of$1.0 million to support our research and development activities. These increases were partially offset by lower consulting services of $0.4 million.We continue to significantly invest in and expand our research and development teams to continuously improve our platform and existingsolutions, as well as develop new solutions and capabilities.Sales and Marketing Expenses Year Ended December 31, Change 2017 2016 $ % (in thousands, except percentages)Sales and marketing $63,855 $58,985 $4,870 8%Percentage of revenues 28% 30% Sales and marketing expenses increased $4.9 million in 2017 compared to 2016, primarily due to an increase in personnel expenses of $3.8million, driven by the increase in the number of employees to support the growth of our business; and increased marketing expenses of $1.2million, including lead generation expense.General and Administrative Expenses Year Ended December 31, Change 2017 2016 $ % (in thousands, except percentages)General and administrative $35,334 $29,114 $6,220 21%Percentage of revenues 15% 15% General and administrative expenses increased $6.2 million in 2017 compared to 2016, primarily driven by an increase in personnel expensesof $7.4 million, principally due to higher executive stock-based compensation and the addition of new employees to support the growth of ourbusiness. The increase was partially offset by lower legal fees of $1.4 million.Total Other Income (Expense), Net52 Table of Contents Year Ended December 31, Change 2017 2016 $ % (in thousands, except percentages)Total other income (expense), net $2,135 $322 $1,813 563%Percentage of revenues 1% 0% Total other income (expense), net increased $1.8 million in 2017 compared to 2016, primarily due to an increase in investment income as ourcash and investment balances increased year over year.Provision for Income Taxes Year Ended December 31, Change 2017 2016 $ % (in thousands, except percentages)(Benefit from) provision for income taxes $(1,062) $11,205 $(12,267) (109)%Percentage of revenues (1)% 5% We recorded an income tax benefit of $1.1 million in 2017 as compared to an income tax provision of $11.2 million in 2016. This was primarilydue to the favorable impact of excess tax benefits from stock-based compensation of $27.1 million due to the adoption of ASU 2016-09 in 2017.This benefit was partially offset by $10.4 million of expense recorded for the re-measuring of deferred tax assets and liabilities due to the decreasein the federal tax rate from 35% to 21% resulting from the Tax Cuts and Jobs Act, enacted into law on December 22, 2017.Liquidity and Capital ResourcesAt December 31, 2018, our principal source of liquidity was cash, cash equivalents and short-term and long-term investments of $365.9million, including $8.0 million of cash held outside of the United States by our foreign subsidiaries. We do not anticipate that we will need fundsgenerated from foreign operations to fund our domestic operations. However, if we repatriate these funds, we could be subject to foreignwithholding taxes.We have experienced positive cash flows from operations during the years ended December 31, 2018, 2017 and 2016. We believe ourexisting cash, cash equivalents, short-term and long-term investments, and cash from operations will be sufficient to fund our operations for atleast the next twelve months. In 2019 we expect capital expenditures to be in a range of $26.0 million to $31.0 million.Our future capital requirements will depend on many factors, including our rate of revenue growth, the expansion of our sales and marketingactivities, the timing, type and extent of our spending on research and development efforts, international expansion and investment in datacenters. We may also seek to invest in or acquire complementary businesses or technologies.Cash FlowsThe following summary of cash flows for the periods indicated has been derived from our consolidated financial statements includedelsewhere in this report: Year Ended December 31, 2018 2017 2016 (in thousands)Cash provided by operating activities $125,464 $107,646 $69,310Cash (used in) investing activities (93,546) (118,195) (96,490)Cash (used in) provided by financing activities (77,483) 10,403 23,419Net decrease in cash, cash equivalents and restricted cash $(45,565) $(146) $(3,761)53 Table of ContentsCash Flows from Operating ActivitiesIn 2018, cash provided by operating activities of $125.5 million was primarily due to $57.3 million of net income, as adjusted by increases indeferred revenues of $24.7 million, attributable to our continued growth in sales; non-cash items including depreciation and amortization expense of$28.9 million and stock-based compensation expense of $30.1 million; and an increase in accounts payable of $3.5 million and other accruedliabilities of $1.4 million. These increases were partially offset by an increase in accounts receivable of $11.5 million due to the timing of customerpayments, and increase in amortization of investment discounts of $1.1 million, and increase in deferred income taxes of $2.5 million and anincrease in prepaid and other assets of $5.0 million.In 2017, cash flows from operating activities of $107.6 million resulted primarily from our net income of approximately $40.4 million, asadjusted by increases in deferred revenues of $29.8 million, attributable to our continued growth in sales; non-cash items including depreciationand amortization expense of $20.6 million and stock-based compensation expense of $27.0 million, and an increase in other noncurrent liabilitiesof $7.3 million, primarily attributable to deferred rent relating to our office facility. These increases were partially offset by an increase in accountsreceivable of $18.0 million due to the timing of customer payments.In 2016, cash flows from operating activities of $69.3 million resulted primarily from our net income of approximately $19.2 million, asadjusted by an increase in deferred revenues of $17.9 million, attributable to our continued growth in sales; accrued liabilities of $9.7 million; non-cash items including depreciation and amortization expense of $17.0 million and stock-based compensation expense of $20.1 million. Theseincreases were partially offset by the non-cash effect of excess tax benefits from stock-based compensation of $8.7 million, an increase in prepaidexpenses and other assets of $2.1 million and an increase in accounts receivable of $4.9 million.Cash Flows from Investing ActivitiesIn 2018, cash used in investing activities of $93.5 million was primarily attributable to net purchases of investments of $54.6 million and$22.8 million of cash used for capital expenditures, including computer hardware and software for our data centers to support our growth, and $13.6million used in connection with our acquisition of Layered Insight and the assets of 1Mobility in addition to $2.5 million for our purchase of aninvestment in a privately-held company.In 2017, cash used in investing activities of $118.2 million was primarily attributable to net purchases of investments of $67.9 million and netcash paid in connection with our acquisitions of Nevis Network (India) Private Limited (Nevis) and Defensative, LLC (NetWatcher) of $12.5 million.Additionally, $37.8 million of cash was used for capital expenditures, including the buildout of our new headquarters facility, computer hardwareand software for our data centers to support our growth and development, and to purchase physical scanner appliances and computer hardwareprovided to certain customers as part of their subscriptions.In 2016, cash used in investing activities of $96.5 million was primarily attributable to net purchases of investments of $73.2 million, arisingfrom cash provided from operating activities. Additionally, $23.2 million of cash was used for capital expenditures, including computer hardwareand software for our data centers to support our growth and development, and to purchase physical scanner appliances and computer hardwareprovided to certain customers as part of their subscriptions.Cash Flows from Financing ActivitiesIn 2018, cash used in financing activities of $77.5 million was primarily attributable to $85.0 million of common stock repurchases and $14.9million of payments related to net share settlement of equity awards, offset by $24.1 million of proceeds from the exercise of stock options.In 2017, cash provided by financing activities of $10.4 million was primarily attributable to $31.3 million of proceeds from the exercise ofstock options, offset by employee payroll taxes paid related to net share settlement of equity awards of $20.9 million.In 2016, cash provided by financing activities of $23.4 million was primarily attributable to $15.2 million of proceeds from the exercise ofstock options and $8.7 million of excess tax benefits from stock-based compensation. 54 Table of ContentsContractual ObligationsOur principal commitments consist of obligations under our outstanding leases for office space, third-party data centers and office equipment.The following table summarizes our contractual cash obligations at December 31, 2018 and the effect such obligations are expected to have onour liquidity and cash flows in future periods: Payment Due by PeriodContractual Obligations Total Less Than1 Year 1-3Years 3-5Years More than 5Years (in thousands) Operating lease obligations $49,638 $8,173 $13,330 $8,836 $19,299Purchase order obligations 21,438 17,978 3,460 — —Total $71,076 $26,151 $16,790 $8,836 $19,299On October 14, 2016, we entered into a lease agreement (included in the table above) for our new headquarters office facility. The leasepayments commenced on May 1, 2018 and the lease has a ten-year term through April 2028. The total remaining commitment of $36.4 million ispayable monthly with escalating rental payments throughout the lease term. In connection with this lease, we have provided the landlord with a$1.2 million standby letter of credit to secure our obligations through the end of the lease term, which is classified as restricted cash in theaccompanying consolidated balance sheets.Operating lease obligations represent our obligations to make payments under the lease agreements for our facilities, data centers, and officeequipment leases. During the year ended December 31, 2018, our rent expense under operating lease obligations was $9.9 million.Off-Balance Sheet ArrangementsDuring the periods presented, we did not have, nor do we currently have, any relationships with unconsolidated entities or financialpartnerships, such as entities often referred to as structured finance or special purpose entities.Recent Accounting PronouncementsSee Note 1 to the consolidated financial statements in Part II, Item 8 of this Annual Report on Form10-K for a discussion of recentaccounting pronouncements.Critical Accounting Policies and EstimatesOur consolidated financial statements are prepared in accordance with U.S. GAAP. The preparation of these financial statements requires usto make estimates and assumptions that affect the reported amounts of assets, liabilities, revenues, expenses and related disclosures. On anongoing basis, we evaluate our estimates and assumptions. Our actual results may differ from these estimates under different assumptions orconditions.We believe that of our significant accounting policies, which are described in the notes to our consolidated financial statements, the followingaccounting policies involve the greatest degree of judgment and complexity and have the greatest potential impact on our consolidated financialstatements. A critical accounting policy is one that is material to the presentation of our consolidated financial statements and requires us to makedifficult, subjective or complex judgments for uncertain matters that could have a material effect on our financial condition and results ofoperations. Accordingly, these are the policies we believe are the most critical to aid in fully understanding and evaluating our financial conditionand results of operations. For further information on all of our significant accounting policies, see Note 1 - The Company and Summary ofSignificant Accounting Policies in the accompanying notes to the consolidated financial statements included in Part II, Item 8, "FinancialStatements and Supplementary Data" of this Annual Report on Form 10-K.Revenue RecognitionWe derive revenues from the sale of subscriptions to our security and compliance solutions, which are delivered on our cloud platform.Subscriptions to our solutions allow customers to access our cloud-based security and compliance solutions through a unified, web-basedinterface. Customers generally enter into one year renewable subscriptions55 Table of Contentsthough some customers do enter into subscriptions with longer terms. The subscription fee entitles the customer to an unlimited number of scansfor a specified number of devices or web applications and, if requested by a customer as part of their subscription, a specified number of physicalor virtual scanner appliances. Our physical and virtual scanner appliances are requested by certain customers as part of their subscriptions inorder to scan IT infrastructures within their firewalls and do not function without, and are not sold separately from, subscriptions for our solutions.In some limited cases, we also provide certain computer equipment used to extend our Qualys Cloud Platform into our customers’ private cloudenvironment. Customers are required to return physical scanner appliances and computer equipment if they do not renew their subscriptions.Subscriptions for unlimited scans and certain limited scan arrangements with firm expiration dates are recognized ratably over the period inwhich the services are performed, generally one year. We recognize revenues on a usage basis for certain other limited scan arrangements, whereexpiration dates can be extended. Physical equipment (scanners and private cloud platforms) are accounted for as operating leases and revenueis recognized ratably over the related subscription period due to the terms of the hardware and software subscriptions being commensurate and thecustomer’s access to our cloud solutions being delivered at the same time or within close proximity to the delivery of the hardware. Costs ofshipping and handling charges associated with physical scanner appliances and other computer equipment are included in cost of revenues.Deferred revenues consist of customer contracts billed or cash received that will be recognized in the future under subscriptions existing atthe balance sheet date.We adopted ASC 606, "Revenue from Contracts with Customers" with a date of initial application of January 1, 2018. We adopted ASC 606using the modified retrospective method and recognized the cumulative effect as an adjustment to the opening balance of equity at January 1,2018. Therefore, the comparative information has not been adjusted and continues to be reported under ASC 605. The significant impact ofadopting ASC 606 was related to the deferral of sales commission costs for new business and when customers increase their renewal orders(“upsells”). We previously expensed sales commission as incurred. Under ASC 606, sales commissions cost related to new business and upsellsare recorded as an asset. We amortize the capitalized commission cost as a selling expense on a straight-line basis over a period of five years.Five years represents the estimated life of the customer relationship taking into account factors such as peer estimates of technology lives andcustomer lives as well as our own historical data. Applying the practical expedient in ASC 340-40-25-4, we expense commissions related torenewals with a contract term of one year or less. The current and noncurrent portions of deferred commissions are included in prepaid expensesand other current assets, and other noncurrent assets, respectively, in our consolidated balance sheets.Income TaxesWe are subject to income taxes in the United States as well as other tax jurisdictions in which we conduct business. Earnings from our non-U.S. activities are subject to local income tax and may also be subject to U.S. income tax.Income tax expense or benefit is recognized for the amount of taxes payable or refundable for the current year, and for deferred tax assetsand liabilities for the tax consequences of events that have been recognized in an entity’s financial statements or tax returns. We must makesignificant assumptions, judgments and estimates to determine our current provision for (benefit from) income taxes, our deferred tax assets andliabilities, and any valuation allowance to be recorded against our deferred tax assets. Our judgments, assumptions and estimates relating to thecurrent provision for (benefit from) income taxes include the geographic mix and amount of income (loss), our interpretation of current tax laws,and possible outcomes of current and future audits conducted by foreign and domestic tax authorities. Our judgments also include anticipating thetax positions we will record in the financial statements before actually preparing and filing the tax returns. Our estimates and assumptions maydiffer from the actual results as reflected in our income tax returns and we record the required adjustments when they are identified or resolved.Changes in our business, tax laws or our interpretation of tax laws, and developments in current and future tax audits, could significantly impactthe amounts provided for income taxes in our results of operations, financial position, or cash flows.Deferred tax assets and liabilities are recognized for the estimated future tax consequences attributable to tax benefit carry-forwards and todifferences between the financial statement amounts of assets and liabilities and their respective tax basis. We regularly review our deferred taxassets for recoverability and establish a valuation allowance if it is more likely than not that some portion or all of the deferred tax assets will notbe realized. To make this assessment, we take into account predictions of the amount and category of taxable income from available positive andnegative evidence about these possible sources of taxable income. The weight given to the potential effect of negative and positive evidence iscommensurate with the extent to which the strength of the evidence can be objectively verified.56 Table of ContentsBased on the analysis of positive and negative factors noted above, we do not have a valuation allowance against U.S. federal and certainstate deferred tax assets. We believe it is more likely than not that our California deferred tax assets will not be realized because the incomeattributed to California is not expected to be sufficient to recognize these deferred tax assets. Accordingly, we continue to record a valuationallowance as of December 31, 2018 for our California deferred tax assets. If, in the future, we determine that these deferred tax assets are morelikely than not to be realized, a release of all or part, of the related valuation allowance could result in an income tax benefit in the period suchdetermination is made.We recognize an income tax expense or benefit with respect to uncertain tax positions in our financial statements that we judge is more likelythan not to be sustained solely on its technical merits in a tax audit, including resolution of any related appeals or litigation processes. To makethis judgment, we must interpret complex and sometimes ambiguous tax laws, regulations and administrative practices. If an income tax positionmeets the more likely than not recognition threshold, then we must measure the amount of the tax benefit to be recognized by determining thelargest amount of tax benefit that has a greater than a 50% likelihood of being realized upon effective settlement with a taxing authority that hasfull knowledge of all of the relevant facts. It is inherently difficult and subjective to estimate such amounts, as this requires us to determine theprobability of various possible settlement outcomes. To determine if a tax position is effectively settled after a tax examination has beencompleted, we must also estimate the likelihood that another taxing authority could review the respective tax position. We must also determinewhen it is reasonably possible that the amount of unrecognized tax benefits will significantly increase or decrease in the 12 months after eachfiscal year-end. These judgments are difficult because a taxing authority may change its behavior as a result of our disclosures in our financialstatements. We must reevaluate our income tax positions on a quarterly basis to consider factors such as changes in facts or circumstances,effectively settled issues under audit, the potential for interest and penalties, and new audit activity. Such a change in recognition or measurementwould result in recognition of a tax benefit or an additional charge to the tax provision.On December 22, 2017, the Tax Cuts and Jobs Act (the “2017 Tax Act”) was enacted into law. The new legislation contains several key taxprovisions that impacted the Company, including the reduction of the corporate income tax rate from 35% to 21% effective January 1, 2018. Thenew legislation also includes a variety of other changes, such as a one-time repatriation tax on accumulated foreign earnings (transition tax),acceleration of business asset expensing, and a reduction in the amount of executive pay that could qualify as a tax deduction, among others.The Company recognized a provisional income tax expense of $10.4 million in the fourth quarter of 2017, from the re-measurement of certaindeferred tax assets and liabilities as a result of the reduction of the federal tax rate, which was included as a component of the income taxprovision on our consolidated statement of income. The Company completed its analysis of the impacts of the 2017 Tax Act in the fourth quarterof 2018 with no material change to its provisional estimate.Stock-Based CompensationWe recognize the fair value of our employee stock options and restricted stock units over the requisite service period for those awardsultimately expected to vest. The fair value of each option is estimated on date of grant using the Black-Scholes-Merton option pricing model andthe fair value of each restricted stock unit is based on the fair value of our stock on the date of grant. Forfeitures are estimated on the date ofgrant and revised if actual or expected forfeiture activity differs materially from original estimates.Determining the appropriate fair value model and calculating the fair value of employee stock options requires the use of highly subjectiveassumptions, including the expected life of the stock option and stock price volatility. The assumptions used in calculating the fair value ofemployee stock options represent management’s best estimates, but the estimates involve inherent uncertainties and the application ofmanagement’s judgment. As a result, if factors change and we use different assumptions, our stock-based compensation expense could bematerially different in the future.We also record compensation representing the fair value of stock options granted to non-employees. Stock-based non-employeecompensation is recognized over the vesting periods of the options. The value of options granted to non-employees is periodically re-measured asthey vest over a performance period.Fair Value MeasurementFair value is defined as the price that would be received to sell an asset or paid to transfer a liability in an orderly transaction between marketparticipants at the measurement date. For certain of our financial instruments, including57 Table of Contentscash and certain cash equivalents, accounts receivable, accounts payable, and other current liabilities, the carrying amounts approximate their fairvalue due to the relatively short maturity of these balances.We measure and report certain cash equivalents, investments and derivative foreign currency forward contracts at fair value in accordancewith the provisions of the authoritative accounting guidance that addresses fair value measurements. This guidance establishes a hierarchy forinputs used in measuring fair value that maximizes the use of observable inputs and minimizes the use of unobservable inputs by requiring thatthe most observable inputs be used when available. The hierarchy is broken down into three levels based on the reliability of inputs as follows:Level 1—Valuations based on quoted prices in active markets for identical assets or liabilities.Level 2—Valuations based on other than quoted prices in active markets for identical assets and liabilities, quoted prices for identical orsimilar assets or liabilities in inactive markets, or other inputs that are observable or can be corroborated by observable market data forsubstantially the full term of the assets or liabilities.Level 3—Valuations based on inputs that are generally unobservable and typically reflect management’s estimates of assumptions thatmarket participants would use in pricing the asset or liability.Our financial instruments consist of assets measured using Level 1 and 2 inputs. Level 1 assets include a highly liquid money market fund,which is valued using unadjusted quoted prices that are available in an active market for an identical asset. Level 2 assets include fixed-incomeU.S. government agency securities, commercial paper, corporate bonds, asset-backed securities and derivative financial instruments consisting offoreign currency forward contracts. The securities, bonds and commercial paper are valued using prices from independent pricing services basedon quoted prices in active markets for similar instruments or on industry models using data inputs such as interest rates and prices that can bedirectly observed or corroborated in active markets. The foreign currency forward contracts are valued using observable inputs.Derivative Financial InstrumentsDerivative financial instruments are utilized by the Company to reduce foreign currency exchange risks. The Company uses foreign currencyforward contracts to mitigate the impact of foreign currency fluctuations of certain non-U.S. dollar denominated asset positions, to date primarilycash and accounts receivable (non-designated), as well as to manage foreign currency fluctuation risk related to forecasted transactions(designated). The Company accounts for these instruments as either non-designated or cash flow hedges, respectively. Open contracts arerecorded within prepaid expenses and other current assets or accrued liabilities in the consolidated balance sheets. Gains and losses resultingfrom currency exchange rate movements on non-designated forward contracts are recognized in other income (expense). Any gains or losses fromderivatives designated as cash flow hedges are first accumulated in AOCI and then reclassified to revenue when the hedged item impacts theconsolidated financial statements.During the year ended December 31, 2018, the Company began a hedging strategy to reduce its exposure to foreign currency exchange ratefluctuations for forecasted subscription renewals and new orders in both GBP and Euro. We use sell-forward currency contracts accounted for ascash flow hedges against a designated portion of forecasted subscription renewals and new orders. Upon executing a hedging contract andquarterly thereafter, the Company assesses hedge effectiveness using regression analysis. The Company includes time value in its effectivenesstesting and the entire change in the value of hedge contracts was recorded as unrealized gains or losses in accumulated other comprehensiveincome (AOCI) within stockholders’ equity on the Company's consolidated balance sheet as of December 31, 2018. The unrealized gains or lossesin AOCI will be reclassified into revenue when the respective hedged transactions affect earnings. As of December 31, 2018, the amount ofunrealized gains and losses related to the hedged forecasted transactions reported in AOCI that is expected to be reclassified into revenue withinthe next 12 months was not material.58 Table of ContentsItem 7A.Quantitative and Qualitative Disclosures about Market RiskWe have domestic and international operations and we are exposed to market risks in the ordinary course of our business. These risksprimarily include interest rate, foreign exchange and inflation risks, as well as risks relating to changes in the general economic conditions in thecountries where we conduct business. To reduce certain of these risks, we monitor the financial condition of our large customers and limit creditexposure by collecting subscription fees in advance.Foreign Currency RiskOur results of operations and cash flows have been and will continue to be subject to fluctuations because of changes in foreign currencyexchange rates, particularly changes in exchange rates between the U.S. dollar and the Euro, British Pound (GBP), and Indian Rupee, thecurrencies of countries where we currently have our most significant international operations. A portion of our invoicing is denominated in the Euro,GBP and Japanese Yen. Our expenses in international locations are generally denominated in the currencies of the countries in which ouroperations are located.The cash flow effects of the Company's derivative contracts for the year ended December 31, 2018 were included within net cash provided byoperating activities on its consolidated statements of cash flows. The Company had notional amounts on foreign currency exchange contractsdesignated as cash flow hedges outstanding of €12.9 million and £4.1 million as of December 31, 2018. The amount of unrealized FX losses onthese contracts were recorded in AOCI and are insignificant. For further details, see Part II, Item 8 of this Annual Report on Form10-K Note 1,Summary of Significant Accounting Policies.Interest Rate SensitivityWe have $365.9 million in cash, cash equivalents and short-term and long-term investments at December 31, 2018. Cash and cashequivalents include cash held in banks, highly liquid money market funds, U.S. government agency securities, and commercial paper.Investments consist of fixed-income U.S. government agency securities, corporate bonds, asset-backed securities and commercial paper. Wedetermine the appropriate balance sheet classification of our investments at the time of purchase and reevaluate such designation at each balancesheet date. We classify our investments as either short-term or long-term based on each instrument's underlying contractual maturity date.The primary objectives of our investment activities are the preservation of principal and support of our liquidity requirements. We do not enterinto investments for trading or speculative purposes. Our investments are subject to market risk due to changes in interest rates, which may affectthe interest income we earn and the fair market value. We do not believe that a 10% increase or decrease in interest rates would have a materialimpact on our operating results or cash flows.59 Table of ContentsItem 8.Financial Statements and Supplementary DataQualys, Inc.INDEX TO CONSOLIDATED FINANCIAL STATEMENTSTable of Contents PageReports of Independent Registered Public Accounting Firm61Consolidated Balance Sheets63Consolidated Statements of Operations64Consolidated Statements of Comprehensive Income65Consolidated Statements of Cash Flows66Consolidated Statements of Stockholders' Equity67Notes to Consolidated Financial Statements6860 Table of ContentsReport of Independent Registered Public Accounting FirmBoard of Directors and StockholdersQualys, Inc.Opinion on the financial statementsWe have audited the accompanying consolidated balance sheets of Qualys, Inc. (a Delaware corporation) and subsidiaries (the “Company”) as ofDecember 31, 2018 and 2017, the related consolidated statements of operations, comprehensive income, stockholders’ equity, and cash flows foreach of the three years in the period ended December 31, 2018, and the related notes and financial statement schedule included under Item 15(a)(2) (collectively referred to as the “financial statements”). In our opinion, the financial statements present fairly, in all material respects, thefinancial position of the Company as of December 31, 2018 and 2017, and the results of its operations and its cash flows for each of the threeyears in the period ended December 31, 2018, in conformity with accounting principles generally accepted in the United States of America.We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (“PCAOB”), theCompany’s internal control over financial reporting as of December 31, 2018, based on criteria established in the 2013 Internal Control-IntegratedFramework issued by the Committee of Sponsoring Organizations of the Treadway Commission (“COSO”), and our report dated February 27, 2019expressed an unqualified opinion.Basis for opinionThese financial statements are the responsibility of the Company’s management. Our responsibility is to express an opinion on the Company’sfinancial statements based on our audits. We are a public accounting firm registered with the PCAOB and are required to be independent withrespect to the Company in accordance with the U.S. federal securities laws and the applicable rules and regulations of the Securities andExchange Commission and the PCAOB.We conducted our audits in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtainreasonable assurance about whether the financial statements are free of material misstatement, whether due to error or fraud. Our audits includedperforming procedures to assess the risks of material misstatement of the financial statements, whether due to error or fraud, and performingprocedures that respond to those risks. Such procedures included examining, on a test basis, evidence supporting the amounts and disclosures inthe financial statements. Our audits also included evaluating the accounting principles used and significant estimates made by management, aswell as evaluating the overall presentation of the financial statements. We believe that our audits provide a reasonable basis for our opinion./s/ GRANT THORNTON LLPWe have served as the Company’s auditor since 2005.San Jose, CaliforniaFebruary 27, 201961 Table of ContentsReport of Independent Registered Public Accounting FirmBoard of Directors and StockholdersQualys, Inc.Opinion on internal control over financial reportingWe have audited the internal control over financial reporting of Qualys, Inc. (a Delaware corporation) and subsidiaries (the “Company”) as ofDecember 31, 2018, based on criteria established in the 2013 Internal Control-Integrated Framework issued by the Committee of SponsoringOrganizations of the Treadway Commission (“COSO”). In our opinion, the Company maintained, in all material respects, effective internal controlover financial reporting as of December 31, 2018, based on criteria established in the 2013 Internal Control-Integrated Framework issued byCOSO.We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (“PCAOB”), theconsolidated financial statements of the Company as of and for the year ended December 31, 2018, and our report dated February 27, 2019expressed an unqualified opinion on those financial statements.Basis for opinionThe Company’s management is responsible for maintaining effective internal control over financial reporting and for its assessment of theeffectiveness of internal control over financial reporting, included in the accompanying Management’s Annual Report on Internal Control overFinancial Reporting (“Management’s Report”). Our responsibility is to express an opinion on the Company’s internal control over financial reportingbased on our audit. We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company inaccordance with the U.S. federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and thePCAOB.We conducted our audit in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtainreasonable assurance about whether effective internal control over financial reporting was maintained in all material respects. Our audit includedobtaining an understanding of internal control over financial reporting, assessing the risk that a material weakness exists, testing and evaluatingthe design and operating effectiveness of internal control based on the assessed risk, and performing such other procedures as we considerednecessary in the circumstances. We believe that our audit provides a reasonable basis for our opinion.Definition and limitations of internal control over financial reportingA company’s internal control over financial reporting is a process designed to provide reasonable assurance regarding the reliability of financialreporting and the preparation of financial statements for external purposes in accordance with generally accepted accounting principles. Acompany’s internal control over financial reporting includes those policies and procedures that (1) pertain to the maintenance of records that, inreasonable detail, accurately and fairly reflect the transactions and dispositions of the assets of the company; (2) provide reasonable assurancethat transactions are recorded as necessary to permit preparation of financial statements in accordance with generally accepted accountingprinciples, and that receipts and expenditures of the company are being made only in accordance with authorizations of management and directorsof the company; and (3) provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use, or disposition ofthe company’s assets that could have a material effect on the financial statements.Because of its inherent limitations, internal control over financial reporting may not prevent or detect misstatements. Also, projections of anyevaluation of effectiveness to future periods are subject to the risk that controls may become inadequate because of changes in conditions, or thatthe degree of compliance with the policies or procedures may deteriorate./s/ GRANT THORNTON LLPSan Jose, CaliforniaFebruary 27, 201962 Table of ContentsQualys, Inc.CONSOLIDATED BALANCE SHEETS(in thousands, except share and per share data) December 31, 2018 2017Assets Current assets: Cash and cash equivalents $41,026 $86,591Short-term marketable securities 248,140 201,823Accounts receivable, net of allowance of $683 and $816 at December 31, 2018 and 2017, respectively 75,825 64,412Prepaid expenses and other current assets 13,974 16,524Total current assets 378,965 369,350Long-term marketable securities 76,710 67,224Property and equipment, net 61,442 58,557Deferred tax assets, net 26,387 25,066Intangible assets, net 21,976 12,401Goodwill 7,225 1,549Long-term investment 2,500 —Restricted cash 1,200 1,200Other noncurrent assets 9,275 2,178Total assets $585,680 $537,525Liabilities and Stockholders’ Equity Current liabilities: Accounts payable $5,588 $1,144Accrued liabilities 25,130 21,444Deferred revenues, current 164,624 143,186Capital lease, current 1,565 —Total current liabilities 196,907 165,774Deferred revenues, noncurrent 20,423 17,136Other noncurrent liabilities 10,361 11,071Total liabilities 227,691 193,981Commitments and contingencies (Note 7) Stockholders’ equity: Preferred stock: $0.001 par value; 20,000,000 shares authorized, no shares issued and outstanding at December 31,2018 and 2017 — —Common stock, $0.001 par value; 1,000,000,000 shares authorized, 39,015,034 and 38,598,117 shares issued andoutstanding at December 31, 2018 and 2017, respectively 39 39Additional paid-in capital 330,572 304,155Accumulated other comprehensive loss (586) (574)Retained earnings 27,964 39,924Total stockholders’ equity 357,989 343,544Total liabilities and stockholders’ equity $585,680 $537,525The accompanying notes are an integral part of these Consolidated Financial Statements.63 Table of ContentsQualys, Inc.CONSOLIDATED STATEMENTS OF OPERATIONS(in thousands, except per share data) Year Ended December 31, 2018 2017 2016Revenues $278,889 $230,828 $197,925Cost of revenues 66,185 51,580 43,128Gross profit 212,704 179,248 154,797Operating expenses: Research and development 53,255 42,816 36,591Sales and marketing 70,039 63,855 58,985General and administrative 39,049 35,334 29,114Total operating expenses 162,343 142,005 124,690Income from operations 50,361 37,243 30,107Other income, net: Interest expense (172) (3) (26)Interest income 6,080 2,674 1,320Other expense, net (801) (536) (972)Total other income, net 5,107 2,135 322Income before income taxes 55,468 39,378 30,429(Benefit from) provision for income taxes (1,836) (1,062) 11,205Net income $57,304 $40,440 $19,224Net income per share: Basic $1.47 $1.08 $0.55Diluted $1.37 $1.01 $0.50Weighted average shares used in computing net income per share: Basic 38,876 37,443 35,247Diluted 41,897 40,071 38,369The accompanying notes are an integral part of these Consolidated Financial Statements.64 Table of ContentsQualys, Inc.CONSOLIDATED STATEMENTS OF COMPREHENSIVE INCOME(in thousands) Year Ended December 31, 2018 2017 2016Net income $57,304 $40,440 $19,224Other comprehensive income (loss): Available-for-sale marketable securities: Change in net unrealized loss, net of tax (261) (462) (57)Reclassification adjustment for net change realized and included in net income, net of tax 289 44 112Total change in unrealized gain (loss) on marketable securities, net of tax 28 (418) 55Cash flow hedges: Change in net unrealized loss, net of tax (40) — —Other comprehensive (loss) income, net of tax (12) (418) 55Comprehensive income $57,292 $40,022 $19,279The accompanying notes are an integral part of these Consolidated Financial Statements.65 Table of ContentsQualys, Inc.CONSOLIDATED STATEMENTS OF CASH FLOWS(in thousands) Year Ended December 31, 2018 2017 2016Cash flows from operating activities: Net income $57,304 $40,440 $19,224Adjustments to reconcile net income to net cash provided by operating activities: Depreciation and amortization expense 28,904 20,636 16,994Bad debt expense 86 657 199Loss on disposal of property and equipment 9 161 55Stock-based compensation 30,090 26,961 20,149Amortization of premiums and accretion of discounts on investments (1,136) 1,324 1,000Excess tax benefits from stock-based compensation — — (8,700)Deferred income taxes (2,521) (2,718) (440)Changes in operating assets and liabilities: Accounts receivable (11,467) (17,966) (4,898)Prepaid expenses and other assets (4,970) (53) (2,107)Accounts payable 3,515 (454) (1,220)Accrued liabilities 1,426 1,485 9,696Deferred revenues 24,725 29,830 17,903Other noncurrent liabilities (501) 7,343 1,455Net cash provided by operating activities 125,464 107,646 69,310Cash flows from investing activities: Purchases of investments (339,862) (299,891) (222,953)Sales and maturities of investments 285,224 231,996 149,708Purchases of property and equipment (22,775) (37,818) (23,245)Business combinations, net of cash acquired (13,633) (12,482) —Purchase of privately-held investment (2,500) — —Net cash used in investing activities (93,546) (118,195) (96,490)Cash flows from financing activities: Repurchase of common stock (85,040) — —Proceeds from exercise of stock options 24,053 31,327 15,157Payments for taxes related to net share settlement of equity awards (14,879) (20,924) (438)Excess tax benefits from stock-based compensation — — 8,700Principal payments under capital lease obligations (1,617) — —Net cash provided by (used in) financing activities (77,483) 10,403 23,419Net decrease in cash and cash equivalents (45,565) (146) (3,761)Cash, cash equivalents and restricted cash at beginning of period 87,791 87,937 $91,698Cash and cash equivalents and restricted cash at end of period $42,226 $87,791 $87,937Supplemental disclosures of cash flow information Cash paid for interest expense $168 $3 $27Cash paid for income taxes, net of refunds 2,693 1,584 856Non-cash investing and financing activities Business acquisitions recorded in Intangible Assets and Accrued liabilities 4,676 1,000 —Purchases of property and equipment recorded in accounts payable and accrued liabilities 4,190 2,765 1,438The accompanying notes are an integral part of these Consolidated Financial Statements.66 Table of ContentsQualys, Inc.CONSOLIDATED STATEMENTS OF STOCKHOLDERS’ EQUITY (in thousands, except share data) Common Stock AdditionalPaid-InCapital AccumulatedOtherComprehensiveIncome (Loss) RetainedEarnings(deficit) TotalStockholders’Equity Shares Amount Balances at December 31, 2015 34,414,631 $34 $223,228 $(211) $(27,485) $195,566Net income — — — — 19,224 19,224Other comprehensive income, net of tax — — — 55 — 55Issuance of common stock upon exercise of stock options 1,399,157 2 15,155 — — 15,157Issuance of common stock upon vesting of restricted stock units 25,213 — — — — —Issuance of common stock in exchange for services 2,000 — 26 — — 26Excess tax benefits from stock-based compensation — — 8,700 — — 8,700Taxes related to net share settlement of equity awards — — (438) — — (438)Stock-based compensation — — 20,123 — — 20,123Balances at December 31, 2016 35,841,001 36 266,794 (156) (8,261) 258,413Cumulative effect of a change in accounting principle related to stock-based compensation — — — — 7,745 7,745Net income — — — — 40,440 40,440Other comprehensive loss, net of tax — — — (418) — (418)Issuance of common stock upon exercise of stock options 2,997,095 3 31,324 — — 31,327Issuance of common stock upon vesting of restricted stock units 217,111 — — — — —Taxes related to net share settlement of equity awards (457,090) — (20,924) — — (20,924)Stock-based compensation — — 26,961 — — 26,961Balances at December 31, 2017 38,598,117 39 304,155 (574) 39,924 343,544Adoption of revenue recognition standard — — — — 2,711 2,711Net income — — — — 57,304 57,304Other comprehensive loss, net of tax — — — (12) — (12)Issuance of common stock upon exercise of stock options 1,183,235 1 24,052 — — 24,053Repurchase of common stock (1,088,899) (1) (13,064) — (71,975) (85,040)Issuance of common stock upon vesting of restricted stock units 524,903 — — — — —Taxes related to net share settlement of equity awards (202,322) — (14,879) — — (14,879)Stock-based compensation — — 30,308 — — 30,308Balances at December 31, 2018 39,015,034 $39 $330,572 $(586) $27,964 $357,989 The accompanying notes are an integral part of these Consolidated Financial Statements.67 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTSNOTE 1.The Company and Summary of Significant Accounting PoliciesDescription of BusinessQualys, Inc. (the “Company”, "we", "us", "our") was incorporated in the state of Delaware on December 30, 1999. The Company isheadquartered in Foster City, California and has wholly-owned subsidiaries throughout the world. The Company is a pioneer and leading provider ofcloud-based security and compliance solutions that enable organizations to identify security risks to their IT infrastructures, help protect their ITsystems and applications from ever-evolving cyber-attacks and achieve compliance with internal policies and external regulations. The Company’scloud solutions address the growing security and compliance complexities and risks that are amplified by the dissolving boundaries betweeninternal and external IT infrastructures and web environments, the rapid adoption of cloud computing and the proliferation of geographicallydispersed IT assets. Organizations can use the Company’s integrated suite of solutions delivered on its Qualys Cloud Platform to cost-effectivelyobtain a unified view of their security and compliance posture across globally-distributed IT infrastructures.Basis of PresentationThe accompanying consolidated financial statements and footnotes have been prepared by the Company in accordance with accountingprinciples generally accepted in the United States (“U.S. GAAP”) as well as the instructions to Form 10-K and the rules and regulations of the U.S.Securities and Exchange Commission ("SEC"). In the opinion of management, the accompanying consolidated financial statements reflect alladjustments, which include only normal recurring adjustments, necessary for the fair presentation of the Company’s consolidated financialposition, results of operations and cash flows for the periods presented. The accompanying consolidated financial statements include the accountsof the Company and its wholly-owned subsidiaries. All significant intercompany transactions and balances have been eliminated uponconsolidation.Use of EstimatesThe preparation of the consolidated financial statements in conformity with U.S. GAAP requires management to make certain estimates andassumptions that affect the reported amounts of assets and liabilities and disclosure of assets and liabilities at the date of the consolidatedfinancial statements and the reported results of operations during the reporting period. The Company’s management regularly assesses theseestimates, which primarily affect revenue recognition, the valuation of accounts receivable, goodwill and intangible assets, capitalization ofinternally developed software, stock-based compensation and the provision for income taxes. Actual results could differ from those estimates andsuch differences may be material to the accompanying consolidated financial statements.Concentration of Credit RiskThe Company invests its cash and cash equivalents with major financial institutions. Cash balances with any one institution at times may bein excess of federally insured limits. Cash equivalents are invested in high-quality investment grade financial instruments and are diversified. TheCompany has not experienced any losses in such accounts and believes it is not exposed to any significant credit risk.Credit risk with respect to accounts receivable is dispersed due to the large number of customers. Collateral is not required for accountsreceivable. As of December 31, 2018 and 2017, no customer or channel partner accounted for more than 10% of the Company's revenues andaccounts receivable balance.Cash, Cash Equivalents, Short-Term and Long-Term InvestmentsCash and cash equivalents include cash held in banks, highly liquid money market funds, commercial paper, and fixed-income U.S.government agency securities, all with original maturities of three months or less when acquired. The Company’s investments consist of fixed-income U.S. government agency securities, corporate bonds, asset-backed securities and commercial paper. Management determines theappropriate classification of the Company's investments at the time of purchase and reevaluates such designation at each balance sheet date.The Company classifies its investments as either short-term or long-term based on each instrument's underlying contractual maturity date.68 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)Cash equivalents are stated at cost, which approximates fair market value. Short-term and long-term investments are classified as available-for-sale and are carried at fair value. Unrealized gains and losses in fair value are reported in other comprehensive income (loss). When theavailable-for-sale securities are sold, cost is based on the specific identification method, and the realized gains and losses are included in otherincome (expense) in the consolidated statements of operations. Short-term and long-term investments are reviewed quarterly for impairment that isdeemed to be other-than-temporary. An investment is considered other-than-temporarily impaired when its fair value is below its amortized costand (1) there is an intent to sell the security, (2) it is “more likely than not” that the security will be sold before recovery of its amortized cost basisor (3) the present value of expected cash flows from the investment is not expected to recover the entire amortized cost basis. Declines in valuethat are considered to be other-than-temporary and adjustments to amortized cost for the amortization of premiums and the accretion of discountsare recorded in other income (expense). Interest and dividends are recorded in interest income as earned.Accounts ReceivableAccounts receivable are recorded at the invoiced amount and do not bear interest. The allowance for doubtful accounts represents theCompany’s best estimate of the amount of probable credit losses and is determined based on a review of existing accounts receivable by agingcategory to identify significant customers or invoices with collectability issues. For those invoices not specifically reviewed, the reserve iscalculated based on the age of the receivable and historical write-offs.Any change in the assumptions used in analyzing a specific account receivable may result in an additional provision for doubtful accountsbeing recognized in the period in which the change occurs. When the Company ultimately concludes that a receivable is uncollectible, the balanceis written off against the allowance for doubtful accounts. Payments subsequently received on such receivables are credited back to the allowancefor doubtful accounts.Cost Method InvestmentsIn the second quarter of fiscal 2018, the Company invested $2.5 million in a privately-held company. The Company used the cost method ofaccounting to account for the investment because it does not hold a controlling interest in this entity and the Company does not have the ability toexercise significant influence over the entity's operating and financial policies. The investment is included in long term assets on theaccompanying consolidated balance sheets. The Company's cost method investment is assessed for impairment when events or changes incircumstances indicate that the carrying amount may not be recoverable. The Company has not recorded any dividends or other-than-temporaryimpairment charges related to its cost method investment. The fair value of the investment is not readily available, and there are no quoted marketprices for the investment.Property and Equipment, netProperty and equipment are stated at cost less accumulated depreciation and amortization. Depreciation is computed using the straight-linemethod over the estimated useful lives of the assets, which range from three to five years. Leasehold improvements are amortized on a straight-line basis over the lesser of the estimated useful life of the asset or the lease term.The Company purchases physical scanner appliances and other computer equipment that are provided to customers on a subscription basis.This equipment is recorded within property and equipment on the accompanying consolidated balance sheet, and the depreciation is recorded tocost of revenues over an estimated useful life of three years.Upon retirement or disposal, the cost of assets and the related accumulated depreciation are removed from the accounts and any resultinggain or loss is reflected in the consolidated statements of operations. Repairs and maintenance that do not extend the life of an asset areexpensed as incurred and major improvements are capitalized as property and equipment.69 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)LeasesOn certain of our operating lease agreements, the Company may receive rent free periods or escalating rent payments over the terms of theleases. The Company recognizes rent expense under these agreements on a straight-line basis over the term of the lease, starting when theCompany takes possession of the property from the landlord. The Company records the difference between the recognized rent expense and theamounts payable under the lease as a short-term or long-term deferred rent liability. When the Company receives tenant allowances upon enteringinto certain leases, the Company records the allowances as an offset to short-term or long-term deferred rent liability and amortizes them using thestraight-line method as a reduction to rent expense over the term of the lease.Impairment of Long-Lived AssetsThe Company evaluates its long-lived assets, which consist of property and equipment, and intangible assets subject to amortization, forindicators of possible impairment when events or changes in circumstances indicate the carrying amount of an asset may not be recoverable.Impairment exists if the carrying amounts of such assets exceed the estimates of future undiscounted cash flows expected to be generated bysuch assets. Should an impairment exist, the impairment loss would be measured based on the excess carrying value of the asset over theasset’s estimated fair value. In each of 2018, 2017 and 2016, the Company had no impairment of long-lived assets.Goodwill and Intangible AssetsGoodwill represents the excess of the purchase price over the fair value of the net tangible and identifiable intangible assets acquired in abusiness combination and is not subject to amortization. Goodwill and other intangible assets with indefinite lives are not amortized, but tested forimpairment annually or if certain circumstances indicate a possible impairment may exist. These tests are performed at the reporting unit level.The Company’s operations are organized as one reporting unit.In testing for a potential impairment of goodwill, the Company first performs a qualitative assessment of its reporting unit to determine if it ismore likely than not (a more than 50% likelihood) that the fair value of the reporting unit is less than its carrying amount. If the fair value is notconsidered to be less than the carrying amount, no further evaluation is necessary. The Company performed the annual qualitative assessment forthe year ended December 31, 2018 and concluded there was no potential impairment of goodwill.In testing for a potential impairment of intangible assets with indefinite lives that are not subject to amortization, the Company first performs aqualitative assessment to determine if it is more likely than not (a more than 50% likelihood) that the fair value of the indefinite-lived intangibleassets is less than the carrying amount. If the fair value is not considered to be less than the carrying amount, no further evaluation is necessary.The Company performs the annual qualitative assessment in the fourth quarter each fiscal year. There were no such impairment losses during2018, 2017 or 2016.If the qualitative assessment indicates there is more than a 50% likelihood that the fair value is less than the carrying amount of the reportingunit or the intangible asset, the Company would perform a two-step test. In the first step, the carrying value of the reporting unit or intangible assetis compared to its estimated fair value. If the estimated fair value is less than the carrying value, then potential impairment exists. In the secondstep, for goodwill, the Company calculates the amount of any impairment by determining the implied fair value of goodwill using a hypotheticalpurchase price allocation, similar to that which would be applied if it were an acquisition and the purchase price was equivalent to fair value ascalculated in the first step. Impairment is equivalent to any excess of goodwill carrying value over its implied fair value. For indefinite-livedintangible assets, the Company performs the currently prescribed quantitative impairment test by comparing the fair value of the indefinite-livedintangible asset with its carrying value.Certain other intangible assets acquired are amortized over their estimated useful lives and tested for impairment if certain circumstancesindicate an impairment may exist. The Company’s intangible assets are comprised primarily of existing technology, patent license, and non-competition agreements and are amortized over periods ranging from three to fourteen years on a straight-line basis. As of December 31, 2018, theCompany has not written down any of these intangible assets as a result of impairment.Internally Developed SoftwareCosts incurred in the development phase are capitalized and amortized over the product’s estimated useful life, which is three years.Capitalized costs include salaries, benefits, and stock-based compensation charges for70 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)employees that are directly involved in developing its cloud security platform during the post planning and implementation phases. Capitalizedcosts related to internally developed software under development are treated as construction in progress until the program, feature or functionalityis ready for its intended use, at which time amortization commences. These capitalized costs are included in other noncurrent assets on theaccompanying consolidated balance sheets. For 2018, 2017 and 2016, the Company capitalized $1.3 million (of which $0.2 million was stock-based compensation), $0.4 million, and zero of costs related to internally developed software, respectively. As of December 31, 2018 and 2017,unamortized internally developed software costs totaled $1.2 million and $0.3 million, respectively. Amortization of internally developed software isreflected in cost of revenues. Costs associated with minor enhancements and maintenance are expensed as incurred. Management evaluates theuseful lives of these assets on an annual basis and tests for impairment whenever events or changes in circumstances occur that could impactthe recoverability of these assets. Business CombinationsWe apply the provisions of ASC 805, Business Combinations, in accounting for our acquisitions. It requires us to recognize separately fromgoodwill the assets acquired and the liabilities assumed at their acquisition date fair values. Goodwill as of the acquisition date is measured as theexcess of consideration transferred over the net of the acquisition date fair values of the assets acquired and the liabilities assumed. While we useour best estimates and assumptions to accurately value assets acquired and liabilities assumed at the acquisition date as well as any contingentconsideration, where applicable, our estimates are inherently uncertain and subject to refinement. As a result, during the measurement period,which may be up to one year from the acquisition date, we record adjustments to the assets acquired and liabilities assumed with thecorresponding offset to goodwill. Upon the conclusion of the measurement period or final determination of the values of assets acquired orliabilities assumed, whichever comes first, any subsequent adjustments are recorded to our consolidated statements of operations.Derivative Financial InstrumentsDerivative financial instruments are utilized by the Company to reduce foreign currency exchange risks. The Company uses foreign currencyforward contracts to mitigate the impact of foreign currency fluctuations of certain non-U.S. dollar denominated asset positions, to date primarilycash and accounts receivable (non-designated), as well as to manage foreign currency fluctuation risk related to forecasted transactions(designated). The Company accounts for these instruments as either non-designated or cash flow hedges, respectively. Open contracts arerecorded within prepaid expenses and other current assets or accrued liabilities in the consolidated balance sheets. Gains and losses resultingfrom currency exchange rate movements on non-designated forward contracts are recognized in other income (expense). Any gains or losses fromderivatives designated as cash flow hedges are first accumulated in other comprehensive income (AOCI) and then reclassified to revenue whenthe hedged item impacts the consolidated financial statements.During the year ended December 31, 2018, the Company began a hedging strategy to reduce its exposure to foreign currency exchange ratefluctuations for forecasted subscription renewals and new orders in both GBP and Euro. We use sell-forward currency contracts accounted for ascash flow hedges against a designated portion of forecasted subscription renewals and new orders. Upon executing a hedging contract andquarterly thereafter, the Company assesses hedge effectiveness using regression analysis. The Company includes time value in its effectivenesstesting and the entire change in the value of hedge contracts was recorded as unrealized gains or losses in accumulated other comprehensiveincome (AOCI) within stockholders’ equity on the Company's consolidated balance sheet as of December 31, 2018. The unrealized gains or lossesin AOCI will be reclassified into revenue when the respective hedged transactions affect earnings. As of December 31, 2018, the amount ofunrealized gains and losses related to the hedged forecasted transactions reported in AOCI that is expected to be reclassified into revenue withinthe next 12 months was not material.The cash flow effects of the Company's derivative contracts for the year ended December 31, 2018 were included within net cash provided byoperating activities on its consolidated statements of cash flows. The Company had notional amounts on foreign currency exchange contractsdesignated as cash flow hedges outstanding of €12.9 million and £4.1 million as of December 31, 2018. The unrealized FX losses on thesecontracts were recorded in AOCI and are insignificant.At December 31, 2018, the Company had two outstanding non-designated forward contracts with notional amounts of €16.0 million and £6.3million, respectively, both with the expiry date of January 31, 2019. At December 31, 2017, the Company had two non-designated outstandingforward contracts with notional amounts of €7.0 million and £4.871 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)million, which expired on January 31, 2018. These forward contracts had insignificant fair value at both December 31, 2018 and 2017. Thesederivatives were not designated as hedges. These instruments were valued using Level 2 inputs.The following summarizes the gains (losses) recognized from non-designated forward contracts and other foreign currency transactions: Year Ended December 31, 2018 2017 2016 Net gains (losses) from forward contracts $543 $(1,665) $554Other foreign currency transaction (losses) gains (1,120) 1,310 (1,324)Total foreign exchange loss, net $(577) $(355) $(770)Stock-Based CompensationThe Company recognizes the fair value of its employee stock options and restricted stock units (RSUs) over the requisite service period forthose awards ultimately expected to vest. The fair value of each option is estimated on date of grant using the Black-Scholes-Merton optionpricing model and the fair value of each restricted stock unit is based on the fair value of the Company's stock on the date of grant. Forfeitures areestimated on the date of grant and revised if actual or expected forfeiture activity differs materially from original estimates.Option grants to non-employees are accounted for at the fair value of the equity instrument issued, as calculated using the Black-Scholes-Merton option-pricing model and the expense is recognized over the vesting periods of the options. The value of options granted to non-employeesis re-measured as they vest over a performance period.Revenue RecognitionThe Company derives revenues from subscriptions that require customers to pay a fee in order to access the Company’s cloud solutions.Customers generally enter into one year renewable subscriptions though some customers do enter into subscriptions with longer terms. Thesubscription fee entitles the customer to an unlimited number of scans for a specified number of networked devices or web applications and, ifrequested by a customer as part of their subscription, a specified number of physical or virtual scanner appliances. Revenue is recognized whencontrol of these subscription services is transferred to our customers, in an amount that reflects the consideration we expect to be entitled to inexchange for those services.The Company’s physical and virtual scanner appliances are requested by certain customers as part of their subscriptions in order to scan ITinfrastructures within their firewalls and do not function without, and are not sold separately from, subscriptions for the Company’s solutions. Insome limited cases, the Company also provides certain computer equipment used to extend its Qualys Cloud Platform into its customers’ privatecloud environment. Customers are required to return physical scanner appliances and computer equipment if they do not renew theirsubscriptions.Physical equipment (scanners and private cloud platforms) are accounted for as operating leases and revenue is recognized over thesubscription term.We determine revenue recognition through the following steps:•Identification of the contract, or contracts, with a customer;•Identification of the performance obligations in the contract;•Determination of the transaction price;•Allocation of the transaction price to the performance obligations in the contract; and•Recognition of revenue when, or as, we satisfy a performance obligation.At the inception of a customer contract, we make an assessment as to that customer's ability to pay for the services provided. We assesscollectability based on a number of factors, including credit worthiness of the customer along with past transaction history. In addition, we performperiodic evaluations of our customers’ financial condition. The Company recognizes revenues for certain limited scan arrangements, for which expiration dates can be extended, on an as-used basis.72 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)Deferred revenues consist of customer contracts billed or cash received that will be recognized in the future under subscriptions existing atthe balance sheet date. The current portion of deferred revenues represents amounts that are expected to be recognized within one year of thebalance sheet date.Costs of shipping and handling charges incurred by the Company associated with physical scanner appliances and other computer equipmentare included in cost of revenues.Sales taxes and other taxes collected from customers to be remitted to government authorities are excluded from revenues.Advertising ExpensesAdvertising costs are expensed as incurred and include costs of advertising and promotional materials. The Company incurred advertisingcosts of $87 thousand, $482 thousand and $124 thousand for 2018, 2017 and 2016, respectively.Income TaxesThe Company provides for the effect of income taxes in its consolidated financial statements using the asset and liability method whichrequires the recognition of deferred tax assets and liabilities for the expected future tax consequences of events that have been included in theconsolidated financial statements. Under this method, deferred tax assets and liabilities are recognized for the future tax consequencesattributable to differences between the financial statement carrying amounts of existing assets and liabilities and their respective tax bases, netoperating loss carryovers, and tax credit carry forwards. Deferred tax assets and liabilities are measured using enacted tax rates expected to applyto taxable income in the years in which those temporary differences are expected to be recovered or settled. The effect on deferred tax assets andliabilities of a change in tax rates is recognized in the period that includes the enactment date.Income tax expense or benefit is recognized for the amount of taxes payable or refundable for the current liabilities for the tax consequencesof events that have been recognized in an entity’s financial statements or significant assumptions, judgments and estimates to determine itscurrent provision (benefit) for income taxes, its deferred tax assets and liabilities, and any valuation allowance to be recorded against its deferredtax assets. The Company's judgments, assumptions and estimates relating to the current provision (benefit) for income taxes include thegeographic mix and amount of income (loss), its possible outcomes of current and future audits conducted by foreign and domestic tax authorities.The anticipating the tax positions the Company will record in the consolidated financial statements before actually preparing and filing the taxreturns. The Company's estimates and assumptions may differ from the actual results as reflected in its income tax required adjustments whenthey are identified or resolved. Changes in the Company's business, tax laws or laws, and developments in current and future tax audits, couldsignificantly impact the amounts provided for income taxes in the Company's results of operations, financial position, or cash flows.Deferred tax assets and liabilities are recognized for the estimated future tax consequences attributable to tax benefit carry-forwards and todifferences between the financial statement amounts of assets and liabilities and their respective tax basis. The Company regularly reviews itsdeferred tax assets for recoverability and establishes a valuation allowance if it is more likely than not that assets will not be realized. To makethis assessment, the Company takes into account predictions of the amount and category of taxable income from various sources and allavailable positive and negative evidence about these possible sources of taxable potential effect of negative and positive evidence iscommensurate with the extent to which the strength of the evidence can be objectively verified.The Company applies a two-step approach to determining the financial statement recognition and measurement of uncertain tax positions.The Company only recognizes an income tax expense or benefit with respect to uncertain tax positions in its financial statements that theCompany judges is more likely than not to be sustained solely on its technical merits in a tax audit, including resolution of any related appeals orlitigation processes. To make this judgment, the Company must interpret complex and sometimes ambiguous tax laws, regulations andadministrative practices. If an income tax position meets the more likely than not recognition threshold, then the Company must measure theamount of the tax benefit to be recognized by determining the largest amount of tax benefit that has a greater than a 50% likelihood of beingrealized upon effective settlement with a taxing authority that has full knowledge of all of the relevant facts. It is inherently difficult and subjectiveto estimate such amounts, as this requires the Company to determine the probability of various possible settlement outcomes. To determine if atax position is effectively settled73 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)after a tax examination has been completed, the Company must also estimate the likelihood that another taxing authority could review therespective tax position. The Company must also determine when it is reasonably possible that the amount of unrecognized tax benefits willsignificantly increase or decrease in the 12 months after each fiscal year-end. These judgments are difficult because a taxing authority maychange its behavior as a result of the Company's disclosures in its financial statements. The Company must reevaluate its income tax positionson a quarterly basis to consider factors such as changes in facts or circumstances, changes in tax law, effectively settled issues under audit, andnew audit activity. Such a change in recognition or measurement would result in recognition of a tax benefit or an additional charge to the taxprovision. The Company's policy is to recognize interest and penalties related to unrecognized tax benefits as a component of the provision forincome taxes.Comprehensive Income (Loss)Other comprehensive income (loss) consists of unrealized gains (losses) on available-for-sale investments, net of tax, and derivativefinancial instruments including our hedging instruments designated as cash flow hedges which are not included in the Company’s net income.Total comprehensive income includes net income and other comprehensive income (loss) and is included in the consolidated statements ofcomprehensive income.Foreign Currency TransactionsThe Company’s operations are conducted in various countries around the world and the financial statements of its foreign subsidiaries arereported in the U.S. dollar as their respective functional currency. Monetary assets and liabilities denominated in foreign currencies have been re-measured into U.S. dollars using the exchange rates in effect at the balance sheet date, and income and expenses are re-measured at averageexchange rates during the period. Foreign currency re-measurement gains and losses and foreign currency transaction gains and losses arerecognized in other income (expense), net. The Company recorded total foreign currency transaction losses of $0.6 million, $0.4 million and $0.8million during 2018, 2017 and 2016, respectively.Fair Value MeasurementsFair value is defined as the price that would be received to sell an asset or paid to transfer a liability in an orderly transaction between marketparticipants at the measurement date. For certain of the Company’s financial instruments, including certain cash equivalents, accounts receivable,accounts payable, and other current liabilities, the carrying amounts approximate their fair value due to the relatively short maturity of thesebalances.The Company measures and reports certain cash equivalents, investments and derivative foreign currency forward contracts at fair value inaccordance with the provisions of the authoritative accounting guidance that addresses fair value measurements. This guidance establishes ahierarchy for inputs used in measuring fair value that maximizes the use of observable inputs and minimizes the use of unobservable inputs byrequiring that the most observable inputs be used when available. The hierarchy is broken down into three levels based on the reliability of inputsas follows:Level 1—Valuations based on quoted prices in active markets for identical assets or liabilities.Level 2—Valuations based on other than quoted prices in active markets for identical assets and liabilities, quoted prices for identical orsimilar assets or liabilities in inactive markets, or other inputs that are observable or can be corroborated by observable market data forsubstantially the full term of the assets or liabilities.Level 3—Valuations based on inputs that are generally unobservable and typically reflect management’s estimates of assumptions thatmarket participants would use in pricing the asset or liability.The Company's financial instruments consist of assets measured using Level 1 and 2 inputs. Level 1 assets include a highly liquid moneymarket fund, which is valued using unadjusted quoted prices that are available in an active market for an identical asset. Level 2 assets includefixed-income U.S. government agency securities, commercial paper, corporate bonds, asset-backed securities and derivative financial instrumentsconsisting of foreign currency forward contracts. The securities, bonds and commercial paper are valued using prices from independent pricingservices based on quoted prices in active markets for similar instruments or on industry models using data inputs such as interest rates andprices that can be directly observed or corroborated in active markets. The foreign currency forward contracts are valued using observable inputs,including currency spot rates, forward points as well as interest rates and credit rates for discounting. See Note 2 for more information regardingthe fair value measurement of the Company's financial instruments.74 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)For the Company's capital leases, its fair value measurement is based on borrowing rates available to the Company for loans with similarterms and maturities, and in consideration of the Company’s credit risk profile, the carrying value of outstanding capital lease obligations (Note 7)approximates fair value (level 2 within the fair value hierarchy).Net Income Per ShareBasic net income per share is computed by dividing net income by the weighted-average number of common shares outstanding during theperiod. All participating securities are excluded from basic weighted average common shares outstanding. In computing diluted net income pershare, undistributed earnings are reallocated to reflect the potential impact of dilutive securities. Diluted net income per share is computed bydividing net income by the weighted-average number of shares of common stock outstanding during the period, adjusted for the effects ofpotentially dilutive common shares, which are comprised of outstanding stock options. The dilutive potential common shares are computed usingthe treasury stock method or the as-if converted method, as applicable. The effects of outstanding stock options are excluded from thecomputation of diluted net income per common share in periods in which the effect would be anti-dilutive.Recently Adopted Accounting PronouncementsThe Company adopted Accounting Standards Codification ("ASC") 606 Revenue from Contracts with Customers with a date of initialapplication of January 1, 2018. The Company adopted ASC 606 using the modified retrospective method and recognized the cumulative effect ofadoption as an adjustment to the opening balance of equity at January 1, 2018. Therefore, the comparative information from the prior period hasnot been adjusted and continues to be reported under ASC 605. The impact of adopting ASC 606 was related to the deferral of sales commissioncosts for new business and when customers increase their renewal orders (“upsells”). The Company previously expensed sales commissions asincurred. Under ASC 606, sales commissions cost related to new business and upsells are recorded as an asset. The Company amortizes thecapitalized commission cost as a selling expense on a straight-line basis over a period of five years. Five years represents the estimated life ofthe customer relationship taking into account factors such as peer estimates of technology lives and customer lives as well as the Company's ownhistorical data. Applying the practical expedient in ASC 340-40-25-4, the Company expenses commissions related to its contract renewals. Thecurrent and noncurrent portions of deferred commissions are included in prepaid expenses and other current assets, and other noncurrent assets,respectively, in its consolidated balance sheets.On January 1, 2018, the Company recorded an increase to retained earnings of $2.7 million, which was the net cumulative impact associatedwith the capitalization of sales commissions. Additionally, the Company recorded a corresponding commission asset balance of $3.5 million and arelated deferred tax liability of $0.8 million. There was no impact to the Company's revenues as a result of adopting ASC 606. See Note 4,“Revenue from Contracts with Customers”, for additional information regarding the impact on the Company's consolidated financial statements.In January 2016, the Financial Accounting Standards Board ("FASB") issued Accounting Standards Update ("ASU") 2016-01, FinancialInstruments - Overall (Subtopic 825-10): Recognition and Measurement of Financial Assets and Financial Liabilities, which impacts certainaspects of recognition, measurement, presentation and disclosure of financial instruments. The ASU impacts the accounting for equityinvestments, financial liabilities under the fair value option, and the presentation and disclosure requirements for financial instruments. TheCompany adopted this ASU in its first quarter of 2018. The adoption of this ASU did not have a material impact on the Company's consolidatedfinancial statements.In August 2016, the FASB issued ASU 2016-15, Classification of Certain Cash Receipts and Cash Payments (a consensus of the EmergingIssues Task Force), to provide guidance on the presentation of certain cash receipts and cash payments in the statement of cash flows in order toreduce diversity in existing practice. The Company adopted this ASU in its first quarter of 2018. The adoption of this ASU did not have a materialimpact on the Company's consolidated financial statements. In November 2016, the FASB issued ASU 2016-18, Statement of Cash Flows (Topic230): Restricted Cash. The update provides guidance on the presentation of restricted cash or restricted cash equivalents in the statement of cashflows. The Company adopted this ASU retrospectively in its first quarter of 2018. The Company reclassified restricted cash of $1.2 million for eachof the three years ended December 31, 2018, 2017 and 2016, in the consolidated statements of cash flows.In January 2017, the FASB issued ASU 2017-01, Business Combinations (Topic 805): Clarifying the Definition of a Business, which revisesthe definition of a business and provides new guidance in evaluating when a set of transferred75 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)assets and activities is a business. The Company adopted this ASU prospectively in its first quarter of 2018. The adoption of this ASU did nothave a material impact on the Company's consolidated financial statements.In August 2017, the FASB issued ASU 2017-12, Derivatives and Hedging (Topic 815): Targeted Improvements to Accounting for HedgingActivities (Topic 815). This standard expands component and fair value hedging, specifies the presentation of the effects of hedging instruments,and eliminates the separate measurement and presentation of hedge ineffectiveness. The Company adopted ASU 2017-12 in the fourth quarter of2018 and has concluded that the adoption had no impact on its consolidated financial statements.In February 2018, the FASB issued ASU 2018-02, Income Statement—Reporting Comprehensive Income (Topic 220): Reclassification ofCertain Tax Effects from Accumulated Other Comprehensive Income (AOCI). This ASU eliminates the stranded tax effects in othercomprehensive income resulting from the Tax Cuts and Jobs Act (the "2017 Tax Act”). Because the amendments only relate to the reclassificationof the income tax effects of the 2017 Tax Act, the underlying guidance that requires that the effect of a change in tax laws or rates be included inincome from continuing operations is not affected. ASU 2018-02 is effective for the Company beginning in the first quarter of fiscal 2019 and earlyadoption is permitted. The Company adopted ASU 2018-02 in the fourth quarter of 2018 and has concluded that the adoption had no impact on itsconsolidated financial statements.Recently Issued Accounting Pronouncements Not Yet AdoptedIn February 2016, the FASB issued ASU 2016-02, Leases (Topic 842), which requires lessees to recognize all leases, including operatingleases, on the balance sheet as a lease asset and lease liability, unless the lease is a short-term lease. ASU 2016-02 also requires additionaldisclosures regarding leasing arrangements. ASU 2016-02 is effective for the Company beginning in the first quarter of fiscal 2019 and earlyadoption is permitted. In July 2018, the FASB issued ASU 2018-11, Targeted Improvements - Leases (Topic 842). This update provides anoptional transition method that allows entities to elect to apply the standard prospectively at its effective date, versus recasting the prior periodspresented. In December 2018, the FASB issued ASU 2018-20, Narrow-Scope Improvements for Lessors - Leases (Topic 842). This update permitslessors, as an accounting policy election, to not evaluate whether certain sales taxes and other similar taxes are lessor costs or lessee costs.Instead, those lessors will account for those costs as if they are lessee costs. Pursuant to the leasing criteria, most of the Company's leasedspace and equipment leases will be required to be accounted for as right-of-use assets on the balance sheet with offsetting financing obligations.In the statement of operations, what was formerly rent expense for operating leases will be lease expense; and finance leases will be bifurcatedinto amortization of right-of-use assets and interest on lease liabilities. The Company plans to adopt the ASU utilizing the current periodadjustment method on January 1, 2019 and to record approximately $37.6 million right-of-use assets and a $41.6 million lease liability on itsconsolidated balance sheet. The amount of the Company's deferred rent as of December 31, 2018 of $4.0 million will be removed upon adoption.In January 2017, the FASB issued ASU 2017-04, Simplifying the Test for Goodwill Impairment (Topic 350). This standard eliminates Step 2from the goodwill impairment test, instead requiring an entity to recognize a goodwill impairment charge for the amount by which the goodwillcarrying amount exceeds the reporting unit’s fair value. This ASU is effective for interim and annual goodwill impairment tests in fiscal yearsbeginning after December 15, 2019 with early adoption permitted. This ASU must be applied on a prospective basis. The adoption of this ASU isnot expected to have a material impact on the Company's consolidated financial statements.In June 2018, the FASB issued ASU 2018-07, Compensation - Stock Compensation (Topic 718): Improvements to Nonemployee Share-Based Payment Accounting. This ASU expands the scope of Topic 718 to include share-based payment transactions for acquiring goods andservices from nonemployees. ASU 2018-07 is effective for the Company beginning in the first quarter of fiscal 2019 and early adoption ispermitted. The Company is currently evaluating the impact of this ASU on its consolidated financial statements.In August 2018, the FASB issued ASU 2018-15, Intangibles - Goodwill and Other - Internal-Use Software (Subtopic 350-40): Customer'sAccounting for Implementation Costs Incurred in a Cloud Computing Arrangement That Is a Service Contract. This ASU aligns the requirementsfor capitalizing implementation costs incurred in a hosting arrangement that is a service contract with the requirements for capitalizingimplementation costs related to internal-use software. ASU 2018-15 is effective for the Company beginning in the first quarter of fiscal 2020 andearly adoption is permitted. The Company is currently evaluating the impact of this ASU on its consolidated financial statements.NOTE 2.Fair Value of Financial Instruments76 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)The Company's cash and cash equivalents, short-term investments, and long-term investments consist of the following: December 31, 2018 Amortized Cost Unrealized Gains Unrealized Losses Fair Value (in thousands)Cash and cash equivalents: Cash $40,913 $— $— $40,913Money market funds 113 — — 113Total 41,026 — — 41,026Short-term marketable securities: Commercial paper 3,237 — — 3,237Corporate bonds 30,906 — (84) 30,822Asset-backed securities 10,447 — (15) 10,432U.S. government agencies 203,734 9 (94) 203,649Total 248,324 9 (193) 248,140Long-term marketable securities: Asset-backed securities 22,945 10 (28) 22,927U.S. government agencies 18,804 — (53) 18,751Corporate bonds 35,322 3 (293) 35,032Total 77,071 13 (374) 76,710Total $366,421 $22 $(567) $365,876 December 31, 2017 Amortized Cost Unrealized Gains Unrealized Losses Fair Value (in thousands)Cash and cash equivalents: Cash $86,500 $— $— $86,500Money market funds 91 — — 91Total 86,591 — — 86,591Short-term investments: Commercial paper 12,623 — (3) 12,620Corporate bonds 38,425 1 (64) 38,362U.S. government agencies 151,058 — (217) 150,841Total 202,106 1 (284) 201,823Long-term investments: Asset-backed securities 4,998 — (12) 4,986U.S. government agencies 24,269 — (54) 24,215Corporate bonds 38,198 — (175) 38,023Total 67,465 — (241) 67,224Total $356,162 $1 $(525) $355,638The following table sets forth by level within the fair value hierarchy the fair value of the Company's available-for-sale securities measured ona recurring basis, excluding cash and money market funds: 77 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued) December 31, 2018 Level 1 Level 2 Level 3 Fair Value (in thousands)Commercial paper $— $3,237 $— $3,237U.S. government agencies — 222,400 — 222,400Corporate bonds — 65,854 — 65,854Asset-backed securities — 33,359 — 33,359Total $— $324,850 $— $324,850 December 31, 2017 Level 1 Level 2 Level 3 Fair Value (in thousands)Commercial paper $— $12,620 $— $12,620U.S. government agencies — 175,056 — 175,056Corporate bonds — 76,385 — 76,385Asset-backed securities — 4,986 — 4,986Total $— $269,047 $— $269,047There were no transfers between Level 1, Level 2 or Level 3 of the fair value hierarchy, as determined at the end of each reporting period.The following summarizes the fair value of securities classified as available-for-sale by contractual maturity: December 31, 2018 Mature within OneYear After One Yearthrough TwoYears Over Two Years Fair Value (in thousands)Commercial paper $3,237 $— $— $3,237U.S. government agencies 203,649 18,751 — 222,400Corporate bonds 30,822 33,531 1,501 65,854Asset-backed securities 29,026 4,333 — 33,359Total $266,734 $56,615 $1,501 $324,85078 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)NOTE 3.Property and Equipment, NetProperty and equipment consist of the following: December 31, 2018 2017 (in thousands)Computer equipment $93,530 $77,883Computer software 26,030 20,447Scanner appliances 15,356 14,325Furniture, fixtures and equipment 5,814 5,075Equipment under capital lease 3,503 —Leasehold improvements 16,439 16,067Total property and equipment 160,672 133,797Less: accumulated depreciation and amortization (99,230) (75,240)Property and equipment, net $61,442 $58,557Physical scanner appliances and other computer equipment that are or will be subject to leases by customers have a net carrying value of$7.9 million and $6.8 million at December 31, 2018 and 2017, respectively, including assets that have not been placed in service of $1.8 millionand $0.9 million, respectively. Other fixed assets not placed in service at December 31, 2018 and 2017 were $3.7 million and $9.6 million,respectively. Depreciation and amortization expense relating to property and equipment was $25.1 million, $19.9 million and 16.6 million for 2018,2017 and 2016, respectively.On November 20, 2017, the Company moved its headquarters office from Redwood City, California to Foster City, California. Due to themove, the Company incurred a loss of disposal of $0.2 million from abandoning the Redwood City office facilities. The gross amount of abandonedcosts was $2.4 million with accumulated depreciation of $2.2 million and a net book value of $0.2 million. The loss was recognized in operatingexpenses.NOTE 4.Revenue from Contracts with CustomersOn January 1, 2018, the Company adopted ASC 606 using the modified retrospective method applied to those contracts which were notcompleted as of that date. Results for reporting periods beginning after January 1, 2018 are presented under ASC 606, while prior period amountsare not adjusted and continue to be reported under the accounting standards in effect for the prior period. The Company implemented internalcontrols to enable the preparation of financial information on adoption. The impact of the standard on the Company's financial statements relates tothe Company's accounting for sales commissions. The Company previously expensed sales commissions as incurred. Under ASC 606, theCompany is required to capitalize certain contract acquisition costs consisting primarily of commissions paid related to new business and upsells.Applying the practical expedient in ASC 340-40-25-4, the Company expenses commissions related to its contract renewals.As a result of the adoption, the Company recorded an increase to retained earnings of $2.7 million as of January 1, 2018, which was the netcumulative impact associated with the capitalization of sales commissions. Additionally, the Company recorded a corresponding commissionasset balance of $3.5 million and a related deferred tax liability of $0.8 million as of January 1, 2018. There was no impact to the Company'srevenues as a result of adopting ASC 606.Incremental direct costs of obtaining a contract, which consist of sales commissions primarily for new business and upsells, are deferredand amortized over the estimated life of the customer relationship if renewals are expected and the renewal commission is not commensurate withthe initial commission. The Company amortizes the capitalized commission cost as a selling expense on a straight-line basis over a period of fiveyears. The Company classifies deferred commissions as current or noncurrent based on the timing of when it expects to recognize the expense.The current and noncurrent portions of deferred commissions are included in prepaid expenses and other current assets and other79 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)noncurrent assets, respectively, in its consolidated balance sheets. Applying the practical expedient in ASC 340-40-25-4, the Company expensescommissions related to its contract renewals that have a contract term of one year or less.Capitalized costs to obtain contracts, current and noncurrent are as follows (in thousands): December 31, 2018 January 1, 2018Commission asset, current$1,480 $704Commission asset, noncurrent$4,692 $2,819For the year ended December 31, 2018, the Company recognized $1.2 million of commission expense from amortization of its commissionassets. During the same period, there was no impairment loss related to the capitalized costs.Contract liabilities (deferred revenue) balances are as follows (in thousands): December 31, 2018 ASC 606 Operating Leases TotalDeferred revenue, current$152,204 $12,420 $164,624Deferred revenue, noncurrent18,286 2,137 20,423Total$170,490 $14,557 $185,047 January 1, 2018 ASC 606 Operating Leases TotalDeferred revenue, current$130,579 $12,607 $143,186Deferred revenue, noncurrent15,419 1,717 17,136Total$145,998 $14,324 $160,322The Company records deferred revenue when cash payments are received or due in advance of its performance. The increase in theCompany's deferred revenue balances is primarily driven by cash payments received or due in advance of satisfying the Company's performanceobligations, offset by revenue recognized in the period. The Company recognized $141.3 million and $112.7 million of subscription revenue duringthe year ended December 31, 2018 and December 31, 2017, respectively, for amount that were included in the deferred revenue balance as ofDecember 31, 2017 and December 31, 2016, respectively.The Company's performance obligation is typically satisfied ratably over the subscription term as its cloud-based offerings are delivered tocustomers electronically and over time. In addition, the Company recognizes revenues for certain limited scan arrangements on an as-used basis.The Company recognizes revenue related to the professional services based on time and materials or completion of milestones stated in thecontracts.As the vast majority of the company’s offerings are subscription based, the company rarely needs to allocate the transaction price to allseparate performance obligations. For contracts that include scanners and PCPs, the company recognizes revenue in proportion to the standaloneselling prices ("SSP") of the underlying services at contract inception. If a SSP is not directly observable, the Company determines the SSP usinginformation that may include market conditions and other observable inputs. The Company typically has more than one SSP for individual productsand services due to the stratification of those products and services by customers and circumstances. In these instances, the Company may useinformation such as the size of the customer and volume purchased in determining the SSP. The Company's transaction prices typically do notinclude variable consideration and area fixed amount for a specific period of time, and the majority of contracts are twelve months with certain customers signing longer term deals. Ingeneral, the Company does not offer rights of return, performance bonuses, customer loyalty programs, payments via non-cash methods, refunds,volume rebates, incentive payments, penalties, price concessions or payments or discounts contingent on future events. Consideration is fixed atthe time of the contract, and governed by the price list to which that particular customer is subject. The Company’s customer and partner-specificpricing is negotiated and agreed upon via individual customer contracts. In some of its contracts, the Company incorporates tiered pricing basedon the number of IP addresses the customer can scan. As customers are required to purchase larger quantities to qualify for the lower-priced tiers,the Company does not grant its customers any material rights. When customers increase their purchased quantities, the Company accounts forthe additional purchased quantities and related price change prospectively as the pricing does not impact subscription services80 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)previously provided. Physical equipment (scanners and private cloud platforms) are accounted for as operating leases and revenue is recognizedover the subscription term. Accounts receivable, net, consists of the following (in thousands): December 31, 2018 January 1, 2018ASC 606 receivables$71,387 $60,984Operating lease receivables5,121 4,244Less: allowance for doubtful accounts(683) (816)Total accounts receivable, net$75,825 $64,412The Company's payment terms vary by the type and location of its customer and the products or services offered. The term betweeninvoicing and when payment is due is not significant. For certain products or services and customer types, the Company requires payment beforethe products or services are delivered to the customer.The following table sets forth the expected revenue from all remaining performance obligations as of December 31, 2018 (in thousands): ASC 606 Expected Revenue Operating Lease ExpectedRevenue Total Expected Revenue2019$46,682 $5,067 $51,749202024,608 2,194 26,802202110,730 1,071 11,80120221,111 39 1,1502023348 9 3572024 and thereafter20 — 20Total$83,499 $8,380 $91,879Revenues allocated to remaining performance obligations represents contracted revenues that have not yet been recognized, which includedeferred revenue from open contracts and the amounts that will be invoiced and recognized as revenues in future periods. Remaining performanceobligations represent the transaction price of firm orders for which service has not been performed and excludes unexercised renewals. TheCompany applied the short-term contract exemption to exclude the remaining performance obligations that are part of a contract that has anoriginal expected duration of one year or less.From time to time, the Company enters into contracts with customers that extend beyond one year, with certain of its customers electing topay for more than one year of services upon contract execution. For any discounts associated with these multiple year contracts, the Companyconcluded our contracts did not contain a financing component.Revenues by sales channel are as follows (in thousands): Year Ended December 31, 2018 ASC 606 Revenue Operating Lease Revenue Total RevenueDirect $148,310 $15,774 $164,084Partner 106,816 7,989 114,805Total $255,126 $23,763 $278,889 Prior periods have not been adjusted under the modified retrospective method.81 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued) Year Ended December 31, 2017 ASC 605 Revenue Operating Lease Revenue Total RevenueDirect $124,355 $15,484 $139,839Partner 84,370 6,619 90,989Total $208,725 $22,103 $230,828 The Company utilizes partners to enable and accelerate the adoption of its cloud platform by increasing its distribution capabilities andmarket awareness of its cloud platform as well as by targeting geographic regions outside the reach of its direct sales force. The Company'schannel partners maintain relationships with their customers throughout the territories in which they operate and provide their customers withservices and third-party solutions to help meet those customers’ evolving security and compliance requirements. As such, these partners mayoffer the Company's IT security and compliance solutions in conjunction with one or more of their own products or services and act as a conduitthrough which the Company can connect with these prospective customers to offer its solutions. For sales involving a channel partner, the channelpartner engages with the prospective customer directly and involves the Company's sales team as needed to assist in developing and closing anorder. When a channel partner secures a sale, the Company sells the associated subscription to the channel partner who in turn resells thesubscription to the customer. Sales to channel partners are made at a discount and revenues are recorded at this discounted price over thesubscription terms. The Company does not have any influence or specific knowledge of its partners' selling terms with their customers. See Note11, "Segment Information and Information about Geographic Area" for disaggregation of revenue by geographic area.NOTE 5.Business CombinationsOn October 16, 2018, the Company completed the acquisition of Layered Insight ("Layered Insight"), a pioneer and global leader in containernative application protection, providing accurate insight into container images, adaptive analysis of running containers, and automated enforcementof the container environment. Total consideration related to the acquisition was $13.4 million, of which $1.6 million is payable in the future subjectto terms and conditions of the purchase agreement. All consideration is payable in cash. The Company also agreed to pay up to an additional $4.0million if the acquired business achieves certain revenue milestones for the annual period ending December 31, 2019. The estimated fair value ofthese milestone payments was determined based on management’s estimate of fair value using a Monte Carlo simulation model, which uses Level3 inputs for fair value measurements. This contingent consideration was included in the component of the purchase price and has been recordedas accrued liabilities in the accompanying consolidated balance sheet as of December 31, 2018 for $1.5 million. In addition to the prior milestone,shareholders of Layered Insight will receive $4.0 million in future payments if certain key employees continue their employment with the Companythrough December 31, 2019. The second milestone is being accounted for as post combinations services and is being expensed into ourconsolidated statement of income. The Company accounted for this acquisition as a business combination and allocated $9.6 million of thepurchase price to technology-based intangible assets and $5.4 million to goodwill. The acquired intangible asset relating to Layered Insight'sdeveloped technology is being amortized over the estimated useful life of approximately four years. Goodwill arising from the Layered Insightacquisition is not deductible for tax purposes.On April 1, 2018, the Company acquired the assets of 1Mobility Private Limited ("1Mobility"), a Singapore-based company. The acquisitionallows the Company to provide enterprises of all sizes with the ability to create and continuously update an inventory of mobile devices on allversions of Android, iOS and Windows Mobile in their environment; and to continuously assess their security and compliance posture, whilequarantining devices that are compromised or out-of-compliance. Total purchase consideration was $4.0 million, of which $0.6 million is payable inthe future subject to terms and conditions of the purchase agreement. The Company accounted for this transaction as a business combination andallocated $3.7 million of the purchase price to technology-based intangible assets and $0.3 million to goodwill. The acquired intangible assetsrelating to 1Mobility's developed technology are being amortized over the estimated useful lives of approximately four years. Goodwill arising fromthe 1Mobility acquisition is deductible for tax purposes over 15 years. The allocation of the consideration for business combinations completed in 2018 is summarized as follows (in thousands):82 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)Acquiree PurchaseConsideration Net Tangible Assets Acquired/(liabilities assumed) PurchasedIntangible Assets Goodwill Deferred TaxLiability1Mobility $4,000 $— $3,700 $300 $—Layered Insight $13,434 $80 $9,600 $5,376 $(1,622)In 2017, the Company purchased certain assets of Nevis Networks (India) Private Limited (“Nevis”) and Defensative, LLC (NetWatcher). TheNevis acquisition accelerates the Company's development of network security solutions for detection and awareness of external intrusions tocomputer networks. The NetWatcher acquisition expands the Company's threat protection and management capabilities and adds new offerings tomanaged security service providers. Total purchase consideration related to the Company’s business combinations was $5.8 million in cash forNevis, and $7.7 million for NetWatcher of which $1.0 million is payable in the future subject to terms and conditions of the purchase agreement.Total cash paid in the business combinations completed during 2017 was $12.5 million. Pro forma financial information for these acquisitions havenot been presented because they are not material to our consolidated financial statements, either individually or in aggregate.In connection with the NetWatcher acquisition, certain founders of NetWatcher will receive future payments with continued employment attheir one year and two-year anniversaries with the Company. These future payments are being recorded as employee compensation expenseratably over the two-year period.The Company accounted for the acquisition of certain assets of Nevis and Netwatcher as business combinations.The allocation of the consideration for business combinations completed in the year of 2017 is summarized as follows (in thousands):Acquiree Purchase Consideration Net Tangible Assets Acquired/(liabilities assumed) Purchased IntangibleAssets GoodwillNevis $5,753 $14 $5,156 $583NetWatcher 7,729 80 7,000 649Total $13,482 $94 $12,156 $1,232Purchased intangible assets represent the estimated fair value of purchased technology from our acquisitions of Nevis and NetWatcher. Theexcess of purchase consideration over the fair value of net tangible and identifiable intangible assets acquired was recorded as goodwill. Goodwillgenerated from these acquisitions was primarily related to the acquired workforce, expected improvements in technology performance andadditional product functionality. The fair values assigned to tangible assets acquired and identifiable intangible assets are based on management'sestimates and assumptions. The intangible assets have an estimated useful life of 5 years. Goodwill is deductible for tax purposes over 15 years.On January 10, 2019, the Company acquired certain assets of Adya, Inc. ("Adya"), a Delaware corporation. Adya’s technology expandsthe Company's solutions to help customers administer their critical SaaS applications from one console, save costs on SaaS licenses, set andenforce security policies in one place, and report and audit on all activity with a single tool. The purchase consideration related to the acquisitionwas $1 million in cash, in addition to $0.2 million and $0.6 million that is payable in the future subject to terms and conditions of the purchaseagreement. The acquisition will be accounted for as an asset purchase.NOTE 6.Goodwill and Intangible Assets, Net83 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)Intangible assets consist primarily of developed technology and patent licenses in business combinations. Acquired intangibles are amortizedon a straight-line basis over the respective estimated useful lives of the assets.During the year ended December 31, 2018, the Company acquired 1Mobility and Layered Insight. These acquisitions resulted in an increaseof developed technology intangible assets of $3.7 million and $9.6 million, respectively.The carrying values of intangible assets as of December 31, 2018 are as follows (in thousands): December 31, 2018 WeightedAverage Lives WeightedRemainingAverage Lives Cost AccumulatedAmortization Net Book ValueDeveloped technology5 years 4 years $25,456 $(4,085) $21,371Patent licenses14 years 6 years 1,387 (822) 565Total intangibles subject to amortization $26,843 $(4,907) 21,936Intangible assets not subject to amortization 40Total intangible assets, net $21,976 December 31, 2017 WeightedAverage Lives WeightedRemainingAverage Lives Cost AccumulatedAmortization Net Book ValueDeveloped technology5 years 5 years $14,067 $(2,371) $11,696Patent licenses14 years 7 years 1,388 (723) 665Total intangibles subject to amortization $15,455 $(3,094) 12,361Intangible assets not subject to amortization 40Total intangible assets, net $12,401Intangible assets amortization expense was $3.7 million and $0.7 million for 2018 and 2017, respectively. As of December 31, 2018, the Company expects amortization expense in future periods to be as follows (in thousands):2019$5,85620205,85620215,85620224,20220231002024 and thereafter66Total expected future amortization expense$21,936Goodwill, which is not subject to amortization, totaled $7.2 million and $1.5 million as of December 31, 2018, and 2017, respectively.Changes in the carrying amount of goodwill for the years ended December 31, 2018, 2017 and 2016 were as follows (in thousands):84 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued) AmountBalance as of December 31, 2016$317Goodwill acquired1,232Balance as of December 31, 20171,549Goodwill acquired5,676Balance as of December 31, 2018$7,225NOTE 7.Commitments and ContingenciesLeasesThe Company leases certain computer equipment and its corporate office and data center facilities under non-cancelable operating leases forvarying periods through 2028.The following are the minimum annual lease payments due under operating leases at December 31, 2018 (in thousands):2019 8,1732020 7,2842021 6,0462022 4,5382023 4,2982024 and thereafter 19,299Total minimum lease payments $49,638Rent expense was $9.9 million, $9.6 million and $7.1 million for 2018, 2017 and 2016, respectively. Although certain of the operating leaseagreements provide for rent free periods or escalating rent payments over the terms of the leases, rent expense under these agreements isrecognized on a straight-line basis over the term of the lease, starting when the Company takes possession of the property from the landlord. Asof December 31, 2018 and 2017, the Company has accrued $10.8 million and $9.5 million of deferred rent related to these agreements, which isreflected in accrued liabilities and other noncurrent liabilities in the accompanying consolidated balance sheets.On October 14, 2016, the Company entered into a lease agreement (included in the table above) for its new headquarters office facility. Thelease payments commenced on May 1, 2018 and the lease has a ten-year term through April 30, 2028. The remaining total commitment as ofDecember 31, 2018 is $36.4 million and is payable monthly with escalating rental payments throughout the lease term. In connection with thislease, the Company provided the landlord with a $1.2 million standby letter of credit to secure the Company’s obligations through the end of thelease term, which was classified as restricted cash in the accompanying consolidated balance sheets.IndemnificationsThe Company from time to time enters into certain types of contracts that contingently require it to indemnify various parties against claimsfrom third parties. These contracts primarily relate to (i) the Company's by-laws, under which it must indemnify directors and executive officers,and may indemnify other officers and employees, for liabilities arising out of their relationship, (ii) contracts under which the Company mustindemnify directors and certain officers for liabilities arising out of their relationship, and (iii) contracts under which the Company may be required toindemnify customers or resellers from certain liabilities arising from potential infringement of intellectual property rights, as well as potentialdamages caused by limited product defects. To date, the Company has not incurred and has not recorded any liability in connection with suchindemnifications.85 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)The Company maintains director and officer insurance, which may cover certain liabilities arising from its obligation to indemnify its directors.ContingenciesThe Company regularly licenses technology from various third party licensors. From time to time, the Company is audited by its licensors forcompliance with the terms of the license agreements. During the quarter ended March 31, 2018, the Company commenced discussions with one ofits vendors with respect to compliance with the terms of the applicable license agreement. During the three months ended June 30, 2018, the auditwas completed and the Company reached a resolution with its licensor. Management sufficiently accrued for licensing agreement matters in thefirst quarter of 2018 and for the year ended December 31, 2018.NOTE 8.Stockholders' Equity and Stock-based CompensationCommon StockThe Company had reserved shares of common stock for future issuance as of December 31, 2018 as follows:Options and RSUs outstanding under equity incentive plans 2000 Equity Incentive Plan 244,6522012 Equity Incentive Plan 4,477,717Shares available for future grants under an equity incentive plan 2012 Equity Incentive Plan 3,817,097Total shares reserved for future issuance 8,539,466Preferred StockEffective October 3, 2012, the Company is authorized to issue 20,000,000 shares of undesignated preferred stock with a par value of $0.001per share. Each series of preferred stock will have such rights and preferences including dividend rights, dividend rate, conversion rights, votingrights, rights and terms of redemption (including sinking fund provisions), redemption price, and liquidation preferences as determined by theBoard. As of December 31, 2018, and 2017, there were no issued or outstanding shares of preferred stock.Stock Options2012 Equity Incentive PlanThe 2012 Equity Incentive Plan (the 2012 Plan) was adopted and approved in September 2012 and became effective on September 26, 2012.Under the 2012 Plan, the Company is authorized to grant to eligible participant's incentive stock options (ISOs), non-statutory stock options(NSOs), stock appreciation rights (SARs), restricted stock awards (RSAs), restricted stock units (RSUs), performance units and performanceshares equivalent to up to 11,791,179 shares of common stock as of December 31, 2018. The number of shares of common stock available forissuance under the 2012 Plan includes an annual increase on January 1 of each year by an amount equal to the least of 3,050,000 shares; 5% ofthe outstanding shares of stock as of the last day of the immediately preceding fiscal year; or an amount determined by the Board of Directors.Options may be granted with an exercise price that is at least equal to the fair market value of the Company's stock at the date of grant and areexercisable when vested. Options granted generally vest over a period of up to four years, with a maximum term of ten years. ISOs may only begranted to employees and any subsidiary corporations' employees. All other awards may be granted to employees, directors and consultants andsubsidiary corporations' employees and consultants. Options, SARs, RSUs, performance units and performance awards may be granted withvesting terms as determined by the Board of Directors and expire no more than ten years after the date of grant or earlier if employment or serviceis terminated. As of December 31, 2018, 3,817,097 shares were available for grant under the 2012 Plan.2000 Equity Incentive Plan86 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)Under the 2000 Equity Incentive Plan (the 2000 Plan), the Company was authorized to grant to eligible participants either ISOs or NSOs. TheISOs were granted at a price per share not less than the fair market value at the date of grant. The NSOs were granted at a price per share notless than 85% of the fair market value at the date of grant. Options granted generally vest over a period of up to four years, with a maximum termof ten years. The 2000 Plan was terminated in connection with the closing of the IPO, and accordingly, no shares are currently available forissuance under the 2000 Plan. The 2000 Plan continues to govern outstanding awards granted thereunder.Options granted under the 2000 Plan were immediately exercisable, and unvested shares are subject to repurchase by the Company. Upontermination of employment of an option holder, the Company has the right to repurchase at the original purchase price any issued but unvestedcommon shares. The amounts paid for shares purchased under an early exercise of stock options and subject to repurchase by the Company arenot reported as a component of stockholders’ equity (deficit) until those shares vest. The amounts received in exchange for these shares arerecorded as an accrued liability in the accompanying consolidated balance sheets and will be reclassified to common stock and additional paid-incapital as the shares vest.Stock-based CompensationStock-based compensation included in the consolidated statements of operations is as follows: Year Ended December 31, 2018 2017 2016 (in thousands)Cost of revenues $2,489 $2,159 $1,858Research and development 7,961 5,944 5,678Sales and marketing 4,650 4,755 4,870General and administrative 14,990 14,103 7,743Total stock-based employee compensation $30,090 $26,961 $20,149Stock-based compensation cost is recognized on a straight-line basis over the service period. Forfeitures are estimated at the time of grantand revised, if necessary, in subsequent periods if actual forfeitures materially differ from those estimates.As of December 31, 2018, the Company had $13.8 million of total unrecognized employee compensation cost related to unvested options thatit expects to recognize over a weighted-average period of 2.1 years.The fair value of each option granted to employees is estimated on the date of grant using the Black-Scholes-Merton option-pricing modelbased on the following assumptions: Year Ended December 31, 2018 2017 2016Expected term (in years) 4.5 to 5.0 5.1 to 5.5 5.0 to 5.9Volatility 45% to 47% 47% to 49% 45% to 49%Risk-free interest rate 2.5% to 3.0% 1.8% to 2.0% 1.1% to 1.3%Dividend yield — — —The expected term of the options is based on evaluations of historical and expected future employee exercise behavior. The risk-free interestrate is based on the U.S. Treasury rates at the date of grant with maturity dates approximately equal to the expected term at the grant date. Priorto the third quarter of 2017, volatility was based on a combination of the historical volatility of the Company and of several public entities that aresimilar to the Company. The Company based volatility on this combination because it did not have sufficient historical transactions in its ownshares on which to solely base expected volatility. Beginning in the third quarter of 2017, the volatility was estimated using the historical volatilityderived from the Company's common stock. The Company has not historically declared any dividends and does not expect to in the future.87 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)Non-Employee Stock-based CompensationThe Company records compensation representing the fair value of stock options granted to non-employees. Stock-based non-employeecompensation was $0.4 million, $0.9 million and $0.7 million for 2018, 2017 and 2016, respectively. Non-employee stock-based compensation isrecognized over the vesting periods of the options. The value of options granted to non-employees is re-measured as they vest over aperformance period.Stock Option Plan ActivityA summary of the Company’s stock option activity is as follows: OutstandingShares WeightedAverageExercisePrice WeightedAverageRemainingContractualLife (Years) AggregateIntrinsicValue (in thousands)Balance as of December 31, 2015 7,579,058 $16.88 5.9 $131,345Granted 2,120,633 $26.64 Exercised (1,399,157) $10.83 Canceled (772,854) $31.57 Balance as of December 31, 2016 7,527,680 $19.25 6.0 $101,717Granted 408,225 $40.82 Exercised (2,997,095) $11.05 Canceled (442,919) $33.29 Balance as of December 31, 2017 4,495,891 $25.29 6.6 $153,129Granted 366,786 $79.79 Exercised (1,183,235) $20.33 Canceled (250,133) $39.61 Balance as of December 31, 2018 3,429,309 $31.79 6.4 $149,935Vested and expected to vest - December 31, 2018 3,230,498 $30.27 6.2 $145,521Exercisable - December 31, 2018 2,459,936 $25.27 5.7 $121,696The following table summarizes the outstanding and vested stock options at December 31, 2018: Outstanding ExercisableExercise Price Number ofShares WeightedAverageExercisePrice PerShare WeightedAverageRemainingContractualLife (Years) Number ofShares WeightedAverageExercisePrice PerShare$2.80 - $12.68 376,405 $8.58 3.1 376,405 $8.58$13.50 - $25.17 474,527 $21.70 5.4 412,956 $21.18$25.56 - $25.56 886,676 $25.56 7.3 587,978 $25.56$26.86 - $26.86 427,997 $26.86 5.1 427,997 $26.86$30.58 - $34.97 372,331 $31.78 6.2 307,743 $31.54$36.25 - $40.15 391,568 $37.78 7.2 225,200 $37.53$40.68 - $59.95 213,744 $49.97 7.6 121,460 $45.16$76.21 - $76.21 101,125 $76.21 9.8 — $—$78.85 - $78.85 78,550 $78.85 9.3 93 $78.85$95.10 - $95.10 106,386 $95.10 9.5 104 $95.10 3,429,309 $31.79 6.4 2,459,936 $25.2788 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)The weighted-average grant date fair value of the Company’s stock options granted during 2018, 2017 and 2016 was $33.05, $18.03 and$11.12, respectively. The aggregate grant date fair value of the Company’s stock options granted during 2018, 2017 and 2016 was $12.1 million,$7.4 million and $23.6 million, respectively.The intrinsic value of options exercised was $71.7 million, $92.1 million and $25.0 million during 2018, 2017 and 2016, respectively. Intrinsicvalue of an option is the difference between the fair value of the Company’s common stock at the time of exercise and the exercise price paid.Restricted StockThe terms and conditions of RSUs include vesting criteria and timing are set by the Board of Directors. The cost of RSUs is determined usingthe fair value of the Company’s common stock on the date of the grant. Compensation cost is recognized on a straight-line basis over the requisiteservice period of each grant adjusted for estimated forfeitures.A summary of the Company’s RSU activity is as follows: Number ofShares Weighted-Average GrantDate Fair Value PerShareBalance as of December 31, 2015 47,500 $37.28Granted 681,350 $28.52Vested (39,998) $27.49Cancelled (101,519) $31.12Balance as of December 31, 2016 587,333 $28.85Granted 1,326,849 $42.69Vested (368,367) $33.52Cancelled (135,227) $32.04Balance as of December 31, 2017 1,410,588 $40.34Granted 548,245 $75.44Vested (525,375) $39.87Cancelled (206,575) $43.43Balance as of December 31, 2018 1,226,883 $55.71Outstanding and expected to vest - December 31, 2018 898,637 $54.67As of December 31, 2018, the Company had $54.3 million of unrecognized compensation cost related to unvested awards that it expects torecognize over a weighted-average period of 2.7 years.On December 21, 2018, the Board of Directors granted an award of time-based and performance-based restricted stock units to theCompany’s Chairman and Chief Executive Officer, Philippe Courtot. The compensation committee of the Board, in consultation with itsindependent compensation consultant, designed these awards so that greater than 50% of this compensation was based on the achievement ofperformance goals linked to metrics designed to drive the creation of shareholder value.The first portion of the award consists of 56,250 time-based stock restricted stock units that will vest in 16 quarterly increments beginning onJanuary 1, 2019, assuming continued service through each applicable vesting date. The second portion of the award consists of 33,089performance-based restricted stock units that vest based on achievement of goals related to revenue growth for a three-year period from January2019 through December 2021 and adjusted EBITDA margin for the 2021 fiscal year, generally conditioned on Mr. Courtot’s continued status as aservice provider through the date that performance is certified. The third portion of the award consists of 33,088 performance-based restrictedstock units that will vest in 3 increments based on the achievement of goals related to revenue growth and adjusted EBITDA margin for each ofthe 2019, 2020, and 2021 fiscal years, generally conditioned on Mr. Courtot’s continued status as a service provider through the date thatperformance is certified for the relevant increment. If Mr. Courtot’s employment (a) is terminated by reason of death or disability or (b) isterminated by the Company for reasons other than cause or good reason within 12 months following a change in control (a “double trigger”termination),89 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)then 100% of any unvested portions of the award will vest, with any vesting in connection with change in control terminations conditioned upon theeffectiveness of a release of claims in favor of the Company.The Company will account for these awards as share-based compensation with multiple performance conditions. and will recognizecompensation cost when it is probable that the performance conditions are met. The Company will assess these conditions on a quarterly basis.As of December 31, 2018, no stock-based compensation cost for these awards has been recognized.Share Repurchase ProgramOn February 5, 2018, the Company's Board of Directors authorized a $100.0 million two-year share repurchase program, which wasannounced on February 12, 2018. The Company's share repurchases may be effected from time to time through open market purchases.Repurchased shares are retired and reclassified as authorized and unissued shares of common stock. On retirement of the repurchased shares,common stock is reduced by an amount equal to the number of shares being retired multiplied by the par value. The excess of the cost of treasurystock that is retired over its par value is first allocated as a reduction to additional paid-in capital based on the initial public offering price of thestock, with the remaining excess to retained earnings.On October 25, 2018, the Company's Board of Directors authorized an additional $100.0 million two-year share repurchase program, whichwas announced on October 30, 2018.During the year ended December 31, 2018, the Company repurchased 1,088,899 shares of its common stock for approximately $85.0 million.All share repurchases were made using cash resources. As of December 31, 2018, approximately $115.0 million remained available for sharerepurchases pursuant to the Company's share repurchase program.401(k) PlanThe Company’s 401(k) Plan (the “401(k) Plan”) was established in 2000 to provide retirement and incidental benefits for its employees. Asallowed under section 401(k) of the Internal Revenue Code, the 401(k) Plan provides tax-deferred salary deductions for eligible employees.Contributions to the 401(k) Plan are limited to a maximum amount as set periodically by the Internal Revenue Service. During the years endedDecember 31, 2018, 2017 and 2016, the Company made contributions to the 401(k) Plan of $1.2 million, and $1.1 million, respectively.NOTE 9.Other Expense, NetOther expense, net consists of the following: Year Ended December 31, 2018 2017 2016 (in thousands)Foreign exchange losses $(577) $(355) $(770)Other expense (224) (181) (202)Other expense, net $(801) $(536) $(972)NOTE 10.Income TaxesThe Company’s geographical breakdown of income before income taxes is as follows:90 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued) Year Ended December 31, 2018 2017 2016 (in thousands)Domestic $50,010 $34,914 $28,982Foreign 5,458 4,464 1,447Income before income taxes $55,468 $39,378 $30,429The provision for (benefit from) income taxes consists of the following: Year Ended December 31, 2018 2017 2016 (in thousands)Current Federal $(90) $22 $8,334State 62 23 1,125Foreign 1,988 1,471 963Total current provision 1,960 1,516 10,422Deferred Federal (3,449) (1,650) 611State 21 (996) 126Foreign (368) 68 46Total deferred (benefit) provision (3,796) (2,578) 783Total (benefit from) provision for income taxes $(1,836) $(1,062) $11,205The reconciliation of the statutory federal income tax rate to the Company’s effective tax rate is as follows: Year Ended December 31, 2018 2017 2016Federal statutory rate 21.0 % 35.0 % 35.0 %State taxes (1.9) (2.1) 2.1Stock-based compensation (20.4) (58.1) 2.4Foreign source income (0.2) (0.2) 0.9Change in valuation allowance 4.4 2.8 1.3Federal rate adjustment (due to 2017 Tax Act) — 26.4 —Federal and state research and development credit (6.7) (5.3) (3.6)Other 0.5 (1.2) (1.3)(Benefit from) provision for income taxes (3.3)% (2.7)% 36.8 %On December 22, 2017, the Tax Cuts and Jobs Act (the “2017 Tax Act”) was enacted into law. The new legislation contains several key taxprovisions that impact the Company, including the reduction of the corporate income tax rate from 35% to 21% effective January 1, 2018. Thenew legislation also includes a variety of other changes, such as a one-time repatriation tax on accumulated foreign earnings (transition tax),acceleration of business asset expensing, and reduction in the amount of executive pay that could qualify as a tax deduction, among others. TheCompany recognized a provisional income tax expense of $10.4 million in the fourth quarter of 2017, from the re-measurement of certain deferredtax assets and liabilities as a result of the reduction of the federal tax rate, which was included as a component of the income tax provision on ourconsolidated statement of income. The Company completed its analysis of the impacts of the 2017 Tax Act in the fourth quarter of 2018 with nomaterial change to its provisional estimate.Deferred Income Taxes91 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)Deferred income taxes reflect the tax effects of temporary differences between the carrying amounts of assets and liabilities for financialreporting purposes and the amounts used for income tax purposes. The components of the Company’s deferred tax assets and liabilities are asfollows: December 31, 2018 2017 (in thousands)Deferred tax assets Net operating loss carryforwards $11,250 $8,947Research and development credit carryforwards 16,901 11,493Foreign tax credit carryforwards 2,209 1,149Accrued liabilities 2,723 1,470Deferred revenues 4,200 3,416Intangible assets — 405Stock-based compensation 6,975 7,135Other 174 196Gross deferred tax assets 44,432 34,211Valuation allowance (9,100) (5,773)Net deferred tax assets 35,332 28,438Deferred tax liabilities Fixed assets (8,161) (3,372)Intangible assets (784) —Total deferred tax liabilities (8,945) (3,372)Net deferred tax assets $26,387 $25,066The realization of deferred tax assets is dependent upon the generation of sufficient taxable income of the appropriate character in futureperiods. The Company regularly assesses the ability to realize its deferred tax assets and establishes a valuation allowance if it is more-likely-than-not that some portion, or all, of the deferred tax assets will not be realized. The Company weighs all available positive and negative evidence,including its earnings history and results of recent operations, scheduled reversals of deferred tax liabilities, projected future taxable income, andtax planning strategies. Due to the weight of objectively verifiable negative evidence, it is more-likely-than-not that its California deferred taxassets will not be realized as of December 31, 2018. Additionally, due to a lack of sufficient future income of the appropriate character, certainU.S. federal and state deferred tax assets are not more-likely-than-not to be realized. Accordingly, the Company has recorded a valuationallowance of $9.1 million against such deferred tax assets. The valuation allowance increased by $3.3 million and $2.1 million during the yearsended December 31, 2018 and 2017, respectively.At December 31, 2018, the Company had federal and state net operating loss carryforwards of approximately $48.4 million and $14.0 million,respectively, available to reduce federal and state taxable income. Federal net operating losses begin to expire in 2021, and state net operatinglosses begin to expire in 2022. Utilization of the Company’s net operating loss carryforwards may be subject to an annual limitation due to theownership change limitations provided by the Internal Revenue Code and similar state provisions. Such an annual limitation could result in theexpiration of the net operating loss carryforwards before utilization. As of December 31, 2018, the Company had $12.2 million of federal and $10.9million of state research and development credit carryforwards, respectively. Federal research and development credits begin to expire in 2022.State research and development credits do not expire. As of December 31, 2018, the Company had foreign tax credit carryforwards of $2.2 millionwhich begin to expire in 2024.The following table summarizes the activity related to the Company’s unrecognized tax benefits:92 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued) Year Ended December 31, 2018 2017 2016 Unrecognized tax benefits beginning balance $5,112 $4,071 $3,506Gross increase for tax positions of prior years 279 66 2Gross decrease for tax positions of prior years (227) — (15)Gross increase for tax positions of current year 1,399 1,101 659Lapse of statute of limitations (157) (126) (81)Total unrecognized tax benefits $6,406 $5,112 $4,071The unrecognized tax benefits, if recognized, would impact the income tax provision by $3.5 million, $2.8 million and $2.4 million as ofDecember 31, 2018, 2017 and 2016, respectively. The remaining amount would be offset by the reversal of related deferred tax assets which aresubject to a full valuation allowance. As of December 31, 2018, the Company does not believe that its estimates, as otherwise provided for, onsuch tax positions will significantly increase or decrease within the next twelve months. The Company has elected to include interest and penaltiesas a component of income tax expense. The amounts were not material for 2018, 2017 and 2016.The Company files income tax returns in the United States, including various state jurisdictions. The Company’s subsidiaries file tax returnsin various foreign jurisdictions. The tax years 2001 through 2018 remain open to examination by the major taxing jurisdictions in which theCompany is subject to tax. As of December 31, 2018, the Company was not under examination by the Internal Revenue Service, foreign, or anymajor state tax jurisdiction.U.S. income tax has not been recognized on the excess of the amount for financial reporting over the tax basis of investments in foreignsubsidiaries that is indefinitely reinvested outside the United States. A determination of the unrecognized deferred tax liability related to this basisdifference is not practicable because of the complexities of the calculation.NOTE 11.Segment Information and Information about Geographic AreaThe Company operates in one segment. The Company’s chief operating decision maker is the Chairman, President and Chief ExecutiveOfficer, who makes operating decisions, assesses performance and allocates resources on a consolidated basis. All of the Company’s principaloperations and decision-making functions are located in the United States. Revenues by geographic area, based on the location of the customer,are as follows: Year Ended December 31, 2018 2017 2016 (in thousands)United States $185,887 $162,681 $139,743Foreign 93,002 68,147 58,182Total revenues $278,889 $230,828 $197,925Property and equipment, net, by geographic area, are as follows: December 31, 2018 2017 (in thousands)United States $59,222 $50,785Foreign 2,220 7,772Total property and equipment, net $61,442 $58,55793 Qualys, Inc.NOTES TO CONSOLIDATED FINANCIAL STATEMENTS (Continued)NOTE 12.Net Income Per ShareThe computations for basic and diluted net income per share are as follows: Year Ended December 31, 2018 2017 2016 (in thousands, except per share data)Numerator: Net income - basic and diluted $57,304 $40,440 $19,224 Denominator: Weighted-average shares used in computing net income per share - basic 38,876 37,443 35,247Effect of potentially dilutive securities: Common stock options 2,401 2,262 3,052RSUs 620 366 70Weighted-average shares used in computing net income per share - diluted 41,897 40,071 38,369Net income per share: Basic $1.47 $1.08 $0.55Diluted $1.37 $1.01 $0.50Potentially dilutive securities not included in the calculation of diluted net income per share because doing so would be anti-dilutive are as follows: Year Ended December 31, 2018 2017 2016 (in thousands)Common stock options 177 742 3,241RSUs 22 71 24NOTE 13.Selected Quarterly Financial Information (Unaudited)The following table shows a summary of the Company's quarterly financial information for each of the quarters in the two-year period endedDecember 31, 2018: Three Months Ended Mar. 31,2017 Jun. 30,2017 Sep. 30, 2017 Dec. 31,2017 Mar. 31,2018 Jun. 30,2018 Sep. 30, 2018 Dec. 31,2018 (unaudited) (in thousands, except per share data)Revenues$53,121 $55,302 $59,490 $62,915 $64,878 $68,153 $71,658 $74,200Income from operations7,656 9,009 10,849 9,729 8,406 10,895 18,117 12,943Other income, net453 360 671 652 1,245 884 1,116 1,862Income before income taxes8,109 9,369 11,520 10,381 9,651 11,779 19,233 14,805Net income21,930 7,202 8,452 2,857 9,142 10,293 23,469 14,400Net income per share: Basic$0.60 $0.19 $0.22 $0.07 $0.24 $0.26 $0.60 $0.37Diluted$0.56 $0.18 $0.21 $0.07 $0.22 $0.24 $0.56 $0.3594 Table of ContentsItem 9.Changes In and Disagreements with Accountants on Accounting and Financial DisclosureNone.Item 9A.Controls and ProceduresEvaluation of Disclosure Controls and ProceduresOur management, with the participation of our Chief Executive Officer, Chief Financial Officer and our Principal Accounting Officer, evaluatedthe effectiveness of our disclosure controls and procedures as of December 31, 2018. The term “disclosure controls and procedures,” as defined inRules 13a-15(e) and 15d-15(e) under the Exchange Act, means controls and other procedures of a company that are designed to ensure thatinformation required to be disclosed by a company in the reports that it files or submits under the Exchange Act is recorded, processed,summarized and reported, within the time periods specified in the Securities and Exchange Commission’s rules and forms. Disclosure controls andprocedures include, without limitation, controls and procedures designed to ensure that information required to be disclosed by a company in thereports that it files or submits under the Exchange Act is accumulated and communicated to the company’s management, including its principalexecutive and principal financial officers, as appropriate to allow timely decisions regarding required disclosure. Management recognizes that anycontrols and procedures, no matter how well designed and operated, can provide only reasonable assurance of achieving their objectives andmanagement necessarily applies its judgment in evaluating the cost-benefit relationship of possible controls and procedures. Based on theevaluation of our disclosure controls and procedures as of December 31, 2018, our Chief Executive Officer and Chief Financial Officer concludedthat, as of such date, our disclosure controls and procedures were effective at the reasonable assurance level.Management's Annual Report on Internal Control over Financial ReportingOur management is responsible for establishing and maintaining adequate internal control over financial reporting, as such term is defined inRules 13a-15(f) and 15d-15(f) of the Exchange Act. Our internal control over financial reporting is a process designed to provide reasonableassurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance withU.S. generally accepted accounting principles, or GAAP. Our internal control over financial reporting includes those policies and procedures that:(i) pertain to the maintenance of records that in reasonable detail accurately and fairly reflect the transactions and dispositions of our assets,(ii) provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance withGAAP, and that our receipts and expenditures are being made only in accordance with authorizations of our management and directors, and(iii) provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use or disposition of our assets that couldhave a material effect on our financial statements.Because of its inherent limitations, internal control over financial reporting may not prevent or detect misstatements. Also, projections of anyevaluation of effectiveness to future periods are subject to the risk that controls may become inadequate because of changes in conditions, or thatthe degree of compliance with the policies or procedures may deteriorate.Under the supervision and with the participation of our management, including our Chief Executive Officer, Chief Financial Officer and our PrincipalAccounting Officer, we conducted an evaluation of the effectiveness of our internal control over financial reporting as of December 31, 2018 basedon the criteria established in the 2013 Internal Control - Integrated Framework issued by the Committee of Sponsoring Organizations of theTreadway Commission, or COSO. Based on our evaluation under the criteria set forth in the 2013 Internal Control - Integrated Framework issuedby the COSO, our management concluded our internal control over financial reporting was effective as of December 31, 2018.The effectiveness of the Company's internal control over financial reporting as of December 31, 2018 has been audited by Grant ThorntonLLP, an independent registered public accounting firm, as stated in its report, which is included in Item 8 of this Annual Report on Form 10-K.95 Table of ContentsChanges in Internal Control over Financial ReportingThere was no change in our internal control over financial reporting identified in connection with the evaluation required by Rule 13a-15(d) and15d-15(d) of the Exchange Act that occurred during the fourth quarter ended December 31, 2018 that has materially affected, or is reasonablylikely to materially affect, our internal control over financial reporting.Item 9B.Other InformationNone.PART IIIItem 10.Directors, Executive Officers and Corporate GovernanceExecutive Officers and DirectorsExcept as set forth below, the information required by this item is incorporated by reference to our Proxy Statement for our 2019 AnnualMeeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year ended December 31, 2018.Codes of Business Conduct and EthicsOur Board of Directors has adopted a code of business conduct and ethics that applies to all of our employees, officers and directors,including our Chief Executive Officer, Chief Financial Officer and other executive and senior financial officers. The code of business conduct andethics is available on our website. We expect that, to the extent required by law, any amendments to the code, or any waivers of its requirements,will be disclosed on our website. We intend to disclose any waiver to the provisions of the code of business conduct and ethics that appliesspecifically to directors or executive officers by filing such information on a Current Report on Form 8-K with the SEC, to the extent such filing isrequired by the NASDAQ Stock Market's listing requirements; otherwise, we will disclose such waiver by posting such information on our website.Item 11.Executive CompensationThe information required by this item is incorporated by reference to our Proxy Statement for our 2019 Annual Meeting of Stockholders to befiled with the SEC within 120 days after the end of the fiscal year ended December 31, 2018.Item 12.Security Ownership of Certain Beneficial Owners and Management and Related StockholderMattersThe information required by this item with respect to Item 403 of Regulation S-K regarding security ownership of certain beneficial owners andmanagement is incorporated by reference to our Proxy Statement for our 2019 Annual Meeting of Stockholders to be filed with the SEC within120 days after the end of the fiscal year ended December 31, 2018. For the information required by this item with respect to Item 201(d) ofRegulation S-K regarding securities authorized for issuance under equity compensation plans, see “Item 5: Market for Registrant’s CommonEquity, Related Stockholder Matters and Issuer Purchases of Equity Securities—Securities Authorized for Issuance under Equity CompensationPlans.”Item 13.Certain Relationships and Related Transactions, and Director IndependenceThe information required by this item is incorporated by reference to our Proxy Statement for our 2019 Annual Meeting of Stockholders to befiled with the SEC within 120 days after the end of the fiscal year ended December 31, 2018.Item 14.Principal Accounting Fees and Services96 Table of ContentsThe information required by this item is incorporated by reference to our Proxy Statement for our 2019 Annual Meeting of Stockholders to befiled with the SEC within 120 days after the end of the fiscal year ended December 31, 2018.97 Table of ContentsPART IVItem 15.Exhibits and Financial Statement Schedules(a)(1) Financial Statements - The financial statements filed as part of this Annual Report on Form 10-K are listed on the Index to ConsolidatedFinancial Statements in Item 8.(a)(2) Financial Statement SchedulesSCHEDULE IISUPPLEMENTARY CONSOLIDATED FINANCIAL STATEMENT SCHEDULEVALUATION AND QUALIFYING ACCOUNTS(in thousands) Additions Balance at Beginningof Year Charged to Costs andExpenses Deductions and Other(1) Balance at End ofYearAllowance for Doubtful Accounts Year Ended December 31, 2018 $816 $85 $(218)$683Year Ended December 31, 2017 $702 $657 $(543)$816Year Ended December 31, 2016 $769 $199 $(266)$702(1) Primarily represents write-offs of uncollectible accounts, net of recoveries.All other schedules have been omitted because they are not required, not applicable, or the required information is otherwise included.(b) Exhibits Incorporated by ReferenceExhibit DescriptionFiledHerewithFormFile No.Exhibit No.Filing DateNumber 3.1 Amended and Restated Certificate of Incorporation of Qualys,Inc. S-1/A333-1820273.3September 12, 2012 3.2 Amended and Restated Bylaws of Qualys, Inc. S-1/A333-1820273.5September 12, 2012 4.1 Form of common stock certificate. S-1/A333-1820274.1September 12, 2012 10.1* 2000 Equity Incentive Plan, as amended, and the form of stockoption agreement thereunder. S-1333-18202710.1June 8, 2012 10.2* 2012 Equity Incentive Plan and forms of agreementsthereunder. S-1/A333-18202710.2September 12, 2012 10.3* Offer Letter, between Qualys, Inc. and Philippe F. Courtot, datedDecember 7, 2000. S-1333-18202710.3June 8, 2012 10.4* Offer Letter, between Qualys, Inc. and Sumedh S. Thakar,dated January 20, 2003. S-1333-18202710.5June 8, 2012 10.5* Offer Letter, between Qualys, Inc. and Melissa B. Fisher, datedApril 15, 2016. 8-K001-3566210.1May 2, 2016 10.6* Offer Letter, between Qualys, Inc. and Bruce K. Posey, datedMay 8, 2012. S-1333-18202710.9June 8, 2012 10.7* Form of director and executive officer indemnificationagreement. S-1/A333-18202710.10August 10, 2012 10.8 Lease Agreement, between Qualys, Inc. and Hudson MetroCenter, LLC, dated October 14, 2016. 8-K001-3566210.1October 19, 2016 10.9* Qualys, Inc. Executive Performance Bonus Plan. Schedule 14A,Appendix A001-35662N/AApril 25, 2016 10.10*† Qualys, Inc. 2016 Corporate Bonus Plan, as amended. 10-Q001-3566210.3August 4, 2016 10.11 Master Services Agreement, between Qualys, Inc. and SavvisCommunications Corporation, dated June 22, 2010. S-1/A333-18202710.14September 12, 2012 10.12† Master Agreement, between Qualys, Inc. and InterouteCommunications Limited, dated March 31, 2008. S-1/A333-18202710.15September 12, 2012 10.13† Manufacturing Services Agreement, between Qualys, Inc. andSynnex Corporation, dated March 1, 2011. S-1/A333-18202710.16September 12, 2012 10.14* Offer Letter, between Qualys, Inc. and Sheila Cheung, datedMarch 8, 2018 8-K001-3566210.1July 31, 2018 21.1 List of subsidiaries of Qualys, Inc.X 23.1 Consent of Grant Thornton LLP, independent registered publicaccounting firm.X 31.1 Certification of Chief Executive Officer pursuant to Rule 13a-14(a) or Rule 15d-14(a) of the Securities Exchange Act of 1934,as adopted pursuant to Section 302 of The Sarbanes-Oxley Actof 2002.X 31.2 Certification of Chief Financial Officer pursuant to Rule 13a-14(a) or Rule 15d-14(a) of the Securities Exchange Act of 1934,as adopted pursuant to Section 302 of The Sarbanes-Oxley Actof 2002.X 31.3 Certification of Principal Accounting Officer pursuant to Rule13a-14(b) or Rule 15d-14(b) of the Securities Exchange Act of1934 and 18 U.S.C. Section 1350 as adopted pursuant toSection 906 of the Sarbanes-Oxley Act of 2002X 32.1 Certification of Chief Executive Officer pursuant to Rule 13a-14(b) or Rule 15d-14(b) of the Securities Exchange Act of 1934and 18 U.S.C. Section 1350 as adopted pursuant to Section 906of The Sarbanes-Oxley Act of 2002.X 32.2 Certification of Chief Financial Officer pursuant to Rule 13a-14(b) or Rule 15d-14(b) of the Securities Exchange Act of 1934and 18 U.S.C. Section 1350 as adopted pursuant to Section 906of The Sarbanes-Oxley Act of 2002.X 32.3 Certification of Principal Accounting Officer pursuant to Rule13a-14(b) or Rule 15d-14(b) of the Securities Exchange Act of1934 and 18 U.S.C. Section 1350 as adopted pursuant toSection 906 of the Sarbanes-Oxley Act of 2002X 101.INS XBRL Instance DocumentX 101.SCH XBRL Taxonomy Extension Schema DocumentX 101.CAL XBRL Taxonomy Extension Calculation Linkbase DocumentX 101.DEF XBRL Taxonomy Extension Definition LinkbaseX 101.LAB XBRL Taxonomy Extension Labels Linkbase DocumentX 101.PRE XBRL Taxonomy Extension Presentation Linkbase DocumentX *Indicates a management contract or compensatory plan orarrangement. †Portions of this exhibit have been omitted due to a determinationby the Securities and Exchange Commission that these portionsshould be granted confidential treatment. 98 Table of ContentsSIGNATURESPursuant to the requirements of Section 13 or 15(d) of the Securities Exchange Act of 1934, the registrant has duly caused this Annual Report on Form 10-Kto be signed on its behalf by the undersigned, thereunto duly authorized, in the City of Foster City, State of California on February 27, 2019. QUALYS, INC. By:/s/ PHILIPPE F. COURTOT Philippe F. Courtot Chairman, President and ChiefExecutive Officer (principal executive officer)99 Table of ContentsPursuant to the requirements of the Securities Exchange Act of 1934, this report has been signed below by the following persons on behalf of the Registrantand in the capacities indicated:Signature TitleDate /s/ PHILIPPE F. COURTOT Chairman, President and ChiefExecutive Officer (principalexecutive officer)February 27, 2019Philippe F. Courtot /s/ MELISSA B. FISHER Chief Financial Officer(principal financial andaccounting officer)February 27, 2019Melissa B. Fisher /s/ SHEILA W. CHEUNG Vice President of Finance;Corporate Controller (PrincipleAccounting Officer)February 27, 2019Sheila W. Cheung /s/ SANDRA E. BERGERON DirectorFebruary 27, 2019Sandra Bergeron /s/ JEFFREY P. HANK DirectorFebruary 27, 2019Jeffrey P. Hank /s/ GENERAL PETER PACE DirectorFebruary 27, 2019General Peter Pace /s/ KRISTI M. ROGERS DirectorFebruary 27, 2019Kristi M. Rogers /s/ PATRICIA HATTER DirectorFebruary 27, 2019Patricia Hatter /s/ JASON REAM DirectorFebruary 27, 2019Jason Ream 100 Exhibit 21.1List of subsidiaries of Qualys, Inc.Name of Subsidiary Jurisdiction of IncorporationQualys International, Inc. United StatesQualys Brazil Desenvolvimento de Produtos e Consultoria de Tecnologiasde Seguranca LTDA. BrazilQualys Canada, Ltd. CanadaQualys Technologies, S.A. FranceQualys GmbH GermanyQualys Hong Kong Limited Hong KongQualys Security TechServices Private Ltd. IndiaQualys Japan K.K. JapanQualys Singapore Pte. Ltd. SingaporeQualys Middle East FZE United Arab EmiratesQualys Ltd. United KingdomQualys Australia Pty Ltd. AustraliaQualys Switzerland Sarl SwitzerlandQualys Colombia S.A.S. ColombiaQualys South Africa Proprietary Limited South AfricaQualys Netherlands B.V. The Netherlands Exhibit 23.1CONSENT OF INDEPENDENT REGISTERED PUBLIC ACCOUNTING FIRMWe have issued our reports dated February 27, 2019 with respect to the consolidated financial statements, schedule and internal control overfinancial reporting included in the Annual Report of Qualys, Inc. on Form 10-K for the year ended December 31, 2018. We consent to theincorporation by reference of said reports in the Registration Statements of Qualys, Inc. on Forms S-8 (File Nos. 333-184394, 333-193576, 333-202587, 333- 209735, 333-216232, and 333-223192)./s/ GRANT THORNTON LLPSan Jose, CaliforniaFebruary 27, 2019 Exhibit 31.1CERTIFICATION OF CHIEF EXECUTIVE OFFICERPURSUANT TO RULE 13a-14(a) OR RULE 15d-14(a)OF THE SECURITIES EXCHANGE ACT OF 1934I, Philippe F. Courtot, certify that:1.I have reviewed this annual report on Form 10-K of Qualys, Inc.;2.Based on my knowledge, this report does not contain any untrue statement of a material fact or omit to state a material fact necessary tomake the statements made, in light of the circumstances under which such statements were made, not misleading with respect to the periodcovered by this report;3.Based on my knowledge, the financial statements, and other financial information included in this report, fairly present in all material respectsthe financial condition, results of operations and cash flows of the registrant as of, and for, the periods presented in this report;4.The registrant’s other certifying officer and I are responsible for establishing and maintaining disclosure controls and procedures (as defined inExchange Act Rules 13a-15(e) and 15d-15(e)) and internal control over financial reporting (as defined in Exchange Act Rules 13a-15(f) and15d-15(f)) for the registrant and have:(a) Designed such disclosure controls and procedures, or caused such disclosure controls and procedures to be designed under oursupervision, to ensure that material information relating to the registrant, including its consolidated subsidiaries, is made known to usby others within those entities, particularly during the period in which this report is being prepared;(b) Designed such internal control over financial reporting, or caused such internal control over financial reporting to be designed under oursupervision, to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statementsfor external purposes in accordance with generally accepted accounting principles;(c) Evaluated the effectiveness of the registrant’s disclosure controls and procedures and presented in this report our conclusions aboutthe effectiveness of the disclosure controls and procedures, as of the end of the period covered by this report based on suchevaluation; and(d) Disclosed in this report any change in the registrant’s internal control over financial reporting that occurred during the registrant’s mostrecent fiscal quarter (the registrant’s fourth fiscal quarter in the case of an annual report) that has materially affected, or is reasonablylikely to materially affect, the registrant’s internal control over financial reporting; and5.The registrant's other certifying officer and I have disclosed, based on our most recent evaluation of internal control over financial reporting, tothe registrant's auditors and the audit committee of the registrant's board of directors (or persons performing the equivalent functions):(a) All significant deficiencies and material weaknesses in the design or operation of internal control over financial reporting which arereasonably likely to adversely affect the registrant's ability to record, process, summarize and report financial information; and(b) Any fraud, whether or not material, that involves management or other employees who have a significant role in the registrant's internalcontrol over financial reporting.Date:February 27, 2019 By:/s/ PHILIPPE F. COURTOT Philippe F. CourtotChairman, President and Chief Executive OfficerQualys, Inc. Exhibit 31.2CERTIFICATION OF CHIEF FINANCIAL OFFICERPURSUANT TO RULE 13a-14(a) OR RULE 15d-14(a)OF THE SECURITIES EXCHANGE ACT OF 1934I, Melissa B. Fisher, certify that:1.I have reviewed this annual report on Form 10-K of Qualys, Inc.;2.Based on my knowledge, this report does not contain any untrue statement of a material fact or omit to state a material fact necessary tomake the statements made, in light of the circumstances under which such statements were made, not misleading with respect to the periodcovered by this report;3.Based on my knowledge, the financial statements, and other financial information included in this report, fairly present in all material respectsthe financial condition, results of operations and cash flows of the registrant as of, and for, the periods presented in this report;4.The registrant's other certifying officer and I are responsible for establishing and maintaining disclosure controls and procedures (as defined inExchange Act Rules 13a-15(e) and 15d-15(e)) and internal control over financial reporting (as defined in Exchange Act Rules 13a-15(f) and15d-15(f)) for the registrant and have:(a) Designed such disclosure controls and procedures, or caused such disclosure controls and procedures to be designed under oursupervision, to ensure that material information relating to the registrant, including its consolidated subsidiaries, is made known to usby others within those entities, particularly during the period in which this report is being prepared;(b) Designed such internal control over financial reporting, or caused such internal control over financial reporting to be designed under oursupervision, to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statementsfor external purposes in accordance with generally accepted accounting principles;(c) Evaluated the effectiveness of the registrant’s disclosure controls and procedures and presented in this report our conclusions aboutthe effectiveness of the disclosure controls and procedures, as of the end of the period covered by this report based on suchevaluation; and(d) Disclosed in this report any change in the registrant’s internal control over financial reporting that occurred during the registrant’s mostrecent fiscal quarter (the registrant’s fourth fiscal quarter in the case of an annual report) that has materially affected, or is reasonablylikely to materially affect, the registrant’s internal control over financial reporting; and5.The registrant's other certifying officer and I have disclosed, based on our most recent evaluation of internal control over financial reporting, tothe registrant's auditors and the audit committee of the registrant's board of directors (or persons performing the equivalent functions):(a) All significant deficiencies and material weaknesses in the design or operation of internal control over financial reporting which arereasonably likely to adversely affect the registrant's ability to record, process, summarize and report financial information; and(b) Any fraud, whether or not material, that involves management or other employees who have a significant role in the registrant's internalcontrol over financial reporting.Date:February 27, 2019 By:/s/ MELISSA B. FISHER Melissa B. FisherChief Financial OfficerQualys, Inc. Exhibit 31.3CERTIFICATION OF CHIEF FINANCIAL OFFICERPURSUANT TO RULE 13a-14(a) OR RULE 15d-14(a)OF THE SECURITIES EXCHANGE ACT OF 1934I, Sheila W. Cheung, certify that:1.I have reviewed this annual report on Form 10-K of Qualys, Inc.;2.Based on my knowledge, this report does not contain any untrue statement of a material fact or omit to state a material fact necessary tomake the statements made, in light of the circumstances under which such statements were made, not misleading with respect to the periodcovered by this report;3.Based on my knowledge, the financial statements, and other financial information included in this report, fairly present in all material respectsthe financial condition, results of operations and cash flows of the registrant as of, and for, the periods presented in this report;4.The registrant's other certifying officer and I are responsible for establishing and maintaining disclosure controls and procedures (as defined inExchange Act Rules 13a-15(e) and 15d-15(e)) and internal control over financial reporting (as defined in Exchange Act Rules 13a-15(f) and15d-15(f)) for the registrant and have:(a) Designed such disclosure controls and procedures, or caused such disclosure controls and procedures to be designed under oursupervision, to ensure that material information relating to the registrant, including its consolidated subsidiaries, is made known to usby others within those entities, particularly during the period in which this report is being prepared;(b) Designed such internal control over financial reporting, or caused such internal control over financial reporting to be designed under oursupervision, to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statementsfor external purposes in accordance with generally accepted accounting principles;(c) Evaluated the effectiveness of the registrant’s disclosure controls and procedures and presented in this report our conclusions aboutthe effectiveness of the disclosure controls and procedures, as of the end of the period covered by this report based on suchevaluation; and(d) Disclosed in this report any change in the registrant’s internal control over financial reporting that occurred during the registrant’s mostrecent fiscal quarter (the registrant’s fourth fiscal quarter in the case of an annual report) that has materially affected, or is reasonablylikely to materially affect, the registrant’s internal control over financial reporting; and5.The registrant's other certifying officer and I have disclosed, based on our most recent evaluation of internal control over financial reporting, tothe registrant's auditors and the audit committee of the registrant's board of directors (or persons performing the equivalent functions):(a) All significant deficiencies and material weaknesses in the design or operation of internal control over financial reporting which arereasonably likely to adversely affect the registrant's ability to record, process, summarize and report financial information; and(b) Any fraud, whether or not material, that involves management or other employees who have a significant role in the registrant's internalcontrol over financial reporting.Date:February 27, 2019 By:/s/ SHEILA W. CHEUNG Sheila W. CheungPrinciple Accounting OfficerQualys, Inc. Exhibit 32.1CERTIFICATION OF CHIEF EXECUTIVE OFFICERPURSUANT TO RULE 13a-14(b) OR RULE 15d-14(b)OF THE SECURITIES EXCHANGE ACT OF 1934 AND 18 U.S.C. SECTION 1350In connection with the Annual Report of Qualys, Inc. (the “Company”) on Form 10-K for the year ended December 31, 2018, as filed with theSecurities and Exchange Commission on the date hereof (the “Report”), I, Philippe F. Courtot, Chairman, President and Chief Executive Officer ofthe Company, certify, pursuant to 18 U.S.C. § 1350, as adopted pursuant to § 906 of the Sarbanes-Oxley Act of 2002, that, to the best of myknowledge: (1) The Report fully complies with the requirements of Section 13(a) or 15(d) of the Securities Exchange Act of 1934; and (2) The information contained in the Report fairly presents, in all material respects, the financial condition and results of operations of theCompany.Date:February 27, 2019 By:/s/ PHILIPPE F. COURTOT Philippe F. CourtotChairman, President and Chief Executive OfficerQualys, Inc. Exhibit 32.2CERTIFICATION OF CHIEF FINANCIAL OFFICERPURSUANT TO RULE 13a-14(b) OR RULE 15d-14(b)OF THE SECURITIES EXCHANGE ACT OF 1934 AND 18 U.S.C. SECTION 1350In connection with the Annual Report of Qualys, Inc. (the “Company”) on Form 10-K for the year ended December 31, 2018, as filed with theSecurities and Exchange Commission on the date hereof (the “Report”), I, Melissa B. Fisher, Chief Financial Officer of the Company, certify,pursuant to 18 U.S.C. § 1350, as adopted pursuant to § 906 of the Sarbanes-Oxley Act of 2002, that, to the best of my knowledge: (1) The Report fully complies with the requirements of Section 13(a) or 15(d) of the Securities Exchange Act of 1934; and (2) The information contained in the Report fairly presents, in all material respects, the financial condition and results of operations of theCompany.Date:February 27, 2019 By:/s/ MELISSA B. FISHER Melissa B. FisherChief Financial OfficerQualys, Inc. Exhibit 32.3CERTIFICATION OF CHIEF FINANCIAL OFFICERPURSUANT TO RULE 13a-14(b) OR RULE 15d-14(b)OF THE SECURITIES EXCHANGE ACT OF 1934 AND 18 U.S.C. SECTION 1350In connection with the Annual Report of Qualys, Inc. (the “Company”) on Form 10-K for the year ended December 31, 2018, as filed with theSecurities and Exchange Commission on the date hereof (the “Report”), I, Sheila W. Cheung, Principle Accounting Officer of the Company, certify,pursuant to 18 U.S.C. § 1350, as adopted pursuant to § 906 of the Sarbanes-Oxley Act of 2002, that, to the best of my knowledge: (1) The Report fully complies with the requirements of Section 13(a) or 15(d) of the Securities Exchange Act of 1934; and (2) The information contained in the Report fairly presents, in all material respects, the financial condition and results of operations of theCompany.Date:February 27, 2019 By:/s/ SHEILA W. CHEUNG Sheila W. CheungPrinciple Accounting OfficerQualys, Inc.

Continue reading text version or see original annual report in PDF format above