S-1.space

Form S-1 · Registration statement · CIK 0001535527 · read the original ↗

CrowdStrike

public company

CRWD · Cybersecurity · filed May 14, 2019 · priced Jun 12, 2019 at $34.00


IPO price $34.00
first-day pop -53%
peak $228
trough $9.89
latest $218
vs IPO +542%
CRWD · monthly closes · 2019-06 → 2026-08
IPO $34.00 peak $218 2019-06 2026-08

CrowdStrike delivered the bull case almost line-for-line — ARR grew more than tenfold, losses turned into billion-dollar free cash flow, and the stock is up over 5x from its $34 IPO — while surviving the single largest IT outage in history, caused by its own software.

When CrowdStrike filed in May 2019 it was a $250M-revenue company with a $519M accumulated deficit, 2,516 subscription customers, and a promise: that a single lightweight cloud agent plus the Threat Graph would replace signature-based antivirus and compound off 147% dollar-based net retention. The IPO priced at $34 on June 12, 2019 — above the raised range — and opened sharply higher; the supplied series records a -52.8% 'first-day' move dated three days before the IPO, which is inconsistent with the widely documented ~70% first-day gain and appears to be a data artifact, so it should not be read as a broken deal.

The operating story then exceeded the prospectus. ARR went from $312.7M at filing to over $4 billion; the customer base grew from thousands into the tens of thousands; the legacy incumbents named as competitors largely dissolved (Symantec and McAfee broken up, Cylance absorbed and marginalized inside BlackBerry, Carbon Black deprecated inside VMware, FireEye split with Mandiant sold to Google). CrowdStrike reached non-GAAP profitability and then its first full year of GAAP net income in fiscal 2024, generated free cash flow margins around 30% versus the -26% shown in the S-1, and joined the S&P 500 in June 2024. The 'unproven market' risk resolved decisively in the bull direction — though Microsoft Defender emerged as a far more formidable bundled competitor than anything the S-1 named, and net retention drifted from 147% toward the low 110s as the base matured.

The risk that actually bit was the one the filing described in its most literal terms: product reliability. On July 19, 2024 a faulty Falcon sensor content update bricked roughly 8.5 million Windows machines worldwide, grounding airlines, halting hospitals and banks, and producing congressional testimony, a $500M+ Delta Air Lines lawsuit, customer-retention concessions and a 5% workforce reduction in 2025. The stock fell roughly 40% from its pre-outage high. What is notable is that the S-1 had disclosed this class of risk precisely — 'our customers have a low tolerance for interruptions of any duration' — even if it framed the danger as a detection miss rather than a bad update crashing endpoints en masse.

The recovery was fast. On the supplied data the stock peaked in August 2026 at +570% versus the $34 IPO price and sits at +542%, with the retention machine largely intact and Falcon Flex re-accelerating module cross-sell. George Kurtz remains CEO. The 'Falcon' brand was never surrendered, the credit-agreement growth covenant that financialized deceleration was retired in favor of convertible notes, and the NSS Labs antitrust overhang evaporated when NSS Labs itself shut down in 2020.

What they promised

best case: exceeded

CrowdStrike positions itself as the pioneer of a cloud-native endpoint security platform (Falcon) that replaces legacy on-premise antivirus, arguing that its single lightweight agent plus Threat Graph data network effects produce a self-reinforcing moat, hyper-growth (revenue up 110% to $249.8M in fiscal 2019), 147% dollar-based net retention, and a path to profitability that has yet to be proven given $519.1M of accumulated deficit.

In the bull case, endpoint security spending shifts decisively from signature-based legacy antivirus to cloud-delivered SaaS, and CrowdStrike is the default winner: subscription revenue compounds off a $312.7M ARR base as customer count grows from 2,516 toward the SMB market and larger enterprises rip out on-premise tools. The land-and-expand engine keeps working — dollar-based net retention of 147% means existing customers alone drive growth as they add endpoints and cross-buy additional cloud modules — while subscription gross margin scales from the 36% seen in fiscal 2017 to roughly 68% in fiscal 2019 and beyond. Operating leverage arrives naturally: operating margin has already improved from (172)% to (55)% and free cash flow burn narrowed from (123)% of revenue to (26)%, so continued growth converts a heavily loss-making income statement into a profitable, cash-generative subscription business with FedRAMP-certified access to government buyers and a channel-leveraged distribution model.

With hindsight: Every quantitative pillar of the bull narrative was surpassed: ARR grew from $312.7M to over $4B, subscription revenue compounded well past the S-1's trajectory, free cash flow margin flipped from -26% to roughly +30%, the company reached GAAP profitability in fiscal 2024, and it entered the S&P 500. The supplied price data shows +542% versus the $34 IPO price as of August 2026 — and the legacy vendors the S-1 named as competitors were largely dismantled or absorbed in the interim.

  • Revenue more than doubled for two consecutive years, reaching $249.8 million in fiscal 2019.

    “Total revenue Total revenue 52,745 52,745 118,752 118,752 249,824” source ↗
  • Subscription customers grew 103% in fiscal 2019 to 2,516, following growth of 173% and 176% in the prior two years.

    “Subscription customers Subscription customers 450 450 1,242 1,242 2,516” source ↗
  • Annual recurring revenue reached $312.7 million as of January 31, 2019, up 121% year over year.

    “Annual recurring revenue Annual recurring revenue 58,758 58,758 141,314 141,314 312,656” source ↗
  • Dollar-based net retention rate reached 147% and has exceeded 100% since January 2016, driven by endpoint expansion and module cross-sell.

    “Since January 2016, our dollar-based net retention rate has consistently exceeded 100%, which is primarily attributable to an expansion of endpoints within, and cross-selling additional cloud modules to, our existing subscription customers.” source ↗
  • Operating margin improved sharply from (172)% in fiscal 2017 to (55)% in fiscal 2019, evidencing scale leverage.

    “Operating margin Operating margin (172 (172 (111 (111 (55” source ↗
  • Free cash flow burn narrowed dramatically as a percentage of revenue, from (123)% to (26)%.

    “Free cash flow margin Free cash flow margin (123 (123 (80 (80 (26” source ↗
  • Subscription revenue nearly tripled year over year and became the dominant revenue line versus professional services.

    “Subscription Subscription 37,895 37,895 92,568 92,568 219,401” source ↗
  • International revenue mix is expanding rapidly, from 13% to 23% of total revenue in two years, supporting a geographic growth vector.

    “We derived approximately 13%, 16%, and 23% of our total revenue from our international customers for fiscal 2017, fiscal 2018, and fiscal 2019, respectively.” source ↗
  • The company holds FedRAMP certification, opening the U.S. federal government channel.

    “although we are currently certified under the Federal” source ↗
  • Deferred revenue of $290.1 million provides visibility into future subscription revenue.

    “Deferred revenue, current and noncurrent Deferred revenue, current and noncurrent 290,067” source ↗

What they warned

15 risks, in the order they mattered

  1. Persistent large losses with no stated path to profitability

    didn't happen

    profitability · structural

    The company has lost money every year since inception, with losses growing in absolute dollars to $140.1 million in fiscal 2019 and a $519.1 million accumulated deficit, and it explicitly declines to predict when profitability will arrive while planning further expense increases.

    “We have incurred net losses in all periods since our inception, and we may not achieve or maintain profitability in the future. We experienced net losses of $91.3 million, $135.5 million,” source ↗

    What happened: CrowdStrike reached non-GAAP profitability and positive free cash flow within two years of listing and posted its first full year of GAAP net income in fiscal 2024 (ended January 31, 2024), with annual free cash flow exceeding $1 billion. GAAP results dipped back into loss in fiscal 2025-26 on outage remediation, restructuring and stock compensation, but the going-concern framing of the S-1 risk never materialized.

  2. Market for cloud-delivered endpoint security is still unproven

    didn't happen

    growth · structural

    The entire thesis rests on enterprises abandoning on-premise antivirus for SaaS security, a transition the company concedes is at an early stage with unpredictable adoption.

    “The use of SaaS solutions to manage and automate security and IT operations is at an early stage and rapidly evolving. As such, it is difficult to predict its potential growth, if any, customer adoption and retention rates, customer demand for our solutions, or the success of existing competitive products.” source ↗

    What happened: Cloud-delivered endpoint protection became the industry default; CrowdStrike's ARR grew from $312.7M at filing to more than $4 billion, and the on-premise incumbents named in the S-1 were broken up, sold or deprecated.

  3. Intense competition from far larger incumbents and well-funded challengers

    partly came true

    competition · structural

    CrowdStrike names McAfee, Symantec, Cylance, Carbon Black, Palo Alto Networks and FireEye as competitors, most with greater resources, broader portfolios, and the ability to bundle endpoint functionality into existing products.

    “Many of these competitors have greater financial, technical, marketing, sales, and other resources, greater name recognition, longer operating histories, and a larger base of customers than we do.” source ↗

    What happened: The specific competitors named — McAfee, Symantec, Cylance, Carbon Black, FireEye — were all dismantled, absorbed or marginalized, but Microsoft Defender bundled into E5 became a far larger threat than anything disclosed, and net retention drifted from 147% toward the low 110s as pricing pressure and SentinelOne/Palo Alto Cortex competition intensified.

  4. Product efficacy failures — real or perceived — could destroy the brand

    came true

    tech & security · structural

    A security platform that misses a novel attack, produces false positives, or is blamed for a customer breach faces reputational damage disproportionate to the technical fault; the company concedes no solution can block all threats.

    “We cannot assure you that our products will detect all cyberattacks, especially in light of the rapidly changing security threat landscape that our solution seeks to address.” source ↗

    What happened: A defective Falcon sensor content update on July 19, 2024 crashed roughly 8.5 million Windows systems worldwide in the largest IT outage on record, grounding flights and halting hospitals; the stock fell about 40% from its pre-outage high, Delta sued for over $500 million, and CEO Kurtz was called before Congress. The company retained the vast majority of customers and the stock recovered to new highs within two years.

  5. The company itself is a high-value target of nation-state attackers and has been attacked before

    partly came true

    tech & security · structural

    Because CrowdStrike publicly attributes attacks to organized cybercriminals and nation-states, it discloses that sophisticated adversaries actively seek to compromise its systems, and that its own Falcon platform has been targeted as an entry point into customer networks.

    “In particular, because we have been involved in the identification of organized cybercriminals and nation-state actors, we have been the subject of intense efforts by sophisticated cyber adversaries who seek to compromise our systems.” source ↗

    What happened: CrowdStrike disclosed in December 2020 that the SolarWinds/Nobelium actors attempted to access its email through a Microsoft reseller account and failed, and in 2025 it acted on an insider who shared internal screenshots with an extortion group. No compromise of the Falcon platform or customer environments via CrowdStrike has been publicly established.

  6. Dependence on Amazon Web Services for platform delivery

    didn't happen

    platform dependence · serious

    Falcon is hosted primarily on AWS; renewal of that agreement may be on materially worse terms, and termination would cause interruptions and delays while alternatives are arranged.

    “because of the importance of AWS' services to our business and AWS' position in the cloud-based server industry, any renegotiation or renewal of our agreement with AWS may be on terms that are significantly less favorable to us than our current agreement.” source ↗

    What happened: The AWS relationship continued without a publicly disclosed disruption or adverse renegotiation; CrowdStrike later expanded its cloud footprint and became a prominent AWS Marketplace partner.

  7. A vast majority of sales flow through channel partners

    didn't happen

    platform dependence · serious

    CrowdStrike does not control the majority of its route to market and expects continued reliance on resellers whose loss or underperformance would directly hit revenue.

    “A vast majority of sales of our Falcon platform flow through our channel partners, and we expect this to continue for the foreseeable future.” source ↗

    What happened: Channel reliance persisted and deepened via MSSP and marketplace routes, but no partner loss or channel disruption has been identified as materially damaging revenue in the post-IPO period.

  8. Short one-year contracts mean revenue must be re-won annually

    partly came true

    growth · serious

    Subscriptions are generally annual with no renewal obligation, and some customers already choose not to renew or reduce module usage — making the 147% net retention figure inherently fragile.

    “Our customers have no obligation to renew their subscription for our Falcon platform after the expiration of their contractual subscription period, which is generally one year, and in the normal course of business, some customers have elected not to renew.” source ↗

    What happened: Gross retention stayed in the high-90s percent range and CrowdStrike shifted toward multi-year Falcon Flex commitments, but dollar-based net retention fell from 147% at IPO to roughly 112% by fiscal 2025, and the July 2024 outage forced customer-commitment packages and discounting that pressured renewals for several quarters.

  9. Trademark challenge to the core Falcon brand by FICO

    didn't happen

    legal · serious

    Fair Isaac Corporation has petitioned to cancel CrowdStrike Falcon trademark registrations and opposed Falcon OverWatch; an adverse outcome could force a costly rebrand of the flagship product.

    “Fair Isaac Corporation, or FICO, petitioned to cancel our trademark registrations and opposed our application. If the appeal board were to find against us, it would cancel our trademark registrations for CrowdStrike Falcon and reject our application to register Falcon OverWatch.” source ↗

    What happened: CrowdStrike never rebranded; Falcon remains the flagship platform name and the product family has expanded (Falcon Complete, Falcon Flex, Charlotte AI) without any forced name change.

  10. Antitrust litigation and civil investigation over cybersecurity testing standard-setting

    didn't happen

    legal · serious

    CrowdStrike and other providers face litigation and a civil investigation alleging that participation in testing standard-setting facilitated a concerted refusal to deal with non-conforming testing organizations.

    “we, along with certain other cybersecurity providers, currently are subject to litigation and a civil investigation regarding participation in cybersecurity testing standard-setting and allegations that this standard-setting facilitated a concerted refusal to deal with cybersecurity testing organizations that did not adhere to those standards.” source ↗

    What happened: The NSS Labs litigation over testing standard-setting was resolved without material impact, and NSS Labs ceased operations in October 2020; no enforcement action against CrowdStrike followed.

  11. Extremely rapid headcount growth strains management and controls

    partly came true

    operations · serious

    Headcount rose from 324 to 1,455 in three years; a large share of the sales force is new and unproductive, and the company must simultaneously build public-company financial controls.

    “our headcount grew from 324 employees as of January 31, 2016, to 550 employees as of January 31, 2017, to 910 employees as of January 31, 2018, to 1,455 employees as of January 31, 2019.” source ↗

    What happened: Headcount grew from 1,455 at filing into the ~10,000 range; the July 2024 outage exposed a real gap in release-testing and staged-rollout controls, and CrowdStrike cut about 5% of staff in May 2025 while restructuring go-to-market.

  12. Privacy and data-protection regulation, including GDPR and CCPA, applied to a platform that ingests customer data

    didn't happen

    regulation · serious

    GDPR fines can reach 4% of worldwide revenue, CCPA compliance work must be finished before January 1, 2020, and Singapore has begun licensing incident response services — a new category of direct regulation for the industry.

    “Administrative fines under the GDPR can amount up to 20 million Euros or four percent of our worldwide annual revenue for the prior fiscal year, whichever is higher.” source ↗

    What happened: No GDPR fine or CCPA enforcement action of material size against CrowdStrike has been publicly reported; the company instead built out regional data residency and FedRAMP High authorizations.

  13. Credit agreement covenants tied to subscription revenue growth and liquidity

    didn't happen

    financing · serious

    The existing credit facility is secured by substantially all assets and requires the company to maintain minimum recurring subscription revenue growth rates — an unusual covenant that converts a growth slowdown into a default risk.

    “our credit agreement includes financial covenants that require us to maintain minimum growth rates of our recurring subscription revenue, and to maintain minimum liquidity at specified levels. We may not be able to generate sufficient cash flow or sales to meet the financial covenants” source ↗

    What happened: The growth-rate covenant risk was extinguished as CrowdStrike refinanced into $750 million of 3.00% senior notes in January 2021 and accumulated multi-billion-dollar cash balances; no covenant breach occurred.

  14. Key person dependence on CEO George Kurtz

    didn't happen

    key person · serious

    The company identifies its CEO as critical to future vision and strategic direction, and notes all executives are employed at will.

    “we are highly dependent on the services of George Kurtz, our Chief Executive Officer, who is critical to our future vision and strategic direction.” source ↗

    What happened: George Kurtz remained CEO throughout, including through the July 2024 outage and congressional testimony; no leadership discontinuity occurred.

  15. Company-generated market size estimates may not materialize

    didn't happen

    market · serious

    The addressable market figures in the prospectus are internal estimates covering all potential participants, and the company warns the market may never materialize.

    “The addressable market we estimate may not materialize for many years, if ever, and even if the markets in which we compete meet the size estimates and growth forecasted in this prospectus, our business could fail to grow at similar rates, if at all.” source ↗

    What happened: CrowdStrike's addressable-market claims proved conservative rather than aspirational: it repeatedly raised its stated TAM as it added cloud security, identity, SIEM and exposure-management modules, and ARR passed $4 billion.

Red flags


  • Net losses grew every year in absolute terms ($91.3M → $135.5M → $140.1M) even as revenue more than doubled, and the filing offers no target date for profitability.
  • Only $88.4 million of cash and cash equivalents on the balance sheet against a $65.6 million annual free cash flow burn, making the IPO proceeds effectively necessary funding rather than optional.
  • Credit facility covenants require maintaining minimum recurring subscription revenue growth rates — a covenant that penalizes any deceleration and is secured by substantially all assets.
  • Customer growth is already decelerating (173% → 176% → 103%), and ARR growth slowed from 140% to 121%.
  • Two live legal overhangs: FICO's challenge to the core 'Falcon' trademark and an antitrust suit plus civil investigation over cybersecurity testing standard-setting.
  • Dual-class structure with Class A shares sold to the public and 131.3 million preferred shares converting into higher-vote Class B common stock.
  • Roughly $10.4 million of stock-based compensation will be recognized immediately upon the IPO for RSUs with performance-based vesting, increasing accumulated deficit to $529.5 million pro forma.
  • Stock-based compensation more than tripled in two years to $20.5 million, and the non-GAAP measures used to frame performance exclude it entirely.
  • The company discloses it has already experienced service interruptions and outages, and that its customers 'have a low tolerance for interruptions of any duration.'

Green flags


  • Dollar-based net retention of 147% is exceptionally high and demonstrates the land-and-expand module cross-sell model working.
  • Subscription gross profit grew from $13.5 million to $150.2 million in two years, showing real margin scaling in the recurring business.
  • Operating margin improved from (172)% to (55)% and free cash flow margin from (123)% to (26)%, indicating genuine operating leverage rather than growth bought at constant loss ratios.
  • Deferred revenue of $290.1 million exceeds trailing annual revenue, providing unusual forward visibility.
  • Subscription revenue (recurring, high-margin) rose to 88% of total revenue as lower-margin professional services shrank as a share of the mix.
  • FedRAMP certification is already in hand, a meaningful barrier for federal sales.
  • The filing candidly discloses its own past targeting by nation-state adversaries and describes concrete internal security practices including tabletop exercises, penetration testing and board-level briefings.
  • The company explicitly cautions that its own market-size estimates are internal and may never materialize — unusual candor for a growth-stage S-1.

How the S-1 reads


The filing is metric-forward and unusually disciplined about definitions — it walks through exactly how ARR and dollar-based net retention are computed, and even volunteers the limitations of its own non-GAAP free cash flow measure ('as free cash flow is negative, we will need to access cash reserves'). Candor is notably high in the security-specific risks: rather than generic breach boilerplate, CrowdStrike states that it has already been targeted by nation-state adversaries and that a compromise of its own systems would be 'especially detrimental,' and it discloses named live disputes (FICO's trademark cancellation petition, an antitrust investigation over testing standard-setting). Two disclosures stand out for their specificity: the credit-agreement covenant requiring minimum subscription revenue growth rates, which effectively financializes deceleration risk, and the counterintuitive admission that a decline in cyberattacks would hurt demand. Governance follows the then-standard Silicon Valley template — a dual-class Class A/Class B structure with 131.3 million preferred shares converting into Class B — and the company claims emerging growth company status to defer auditor attestation on internal controls.

  • “As a cybersecurity provider, we have been, and expect to continue to be, a target of cyberattacks. If our internal networks, systems, or data are or are perceived to have been compromised, our reputation may be damaged and our financial results may be negatively affected.” source ↗

    The company frames its self-defense posture with unusual specificity, acknowledging it is a marked target.

  • “While we have experienced significant growth in revenue in recent periods, we cannot predict when or whether we will reach or maintain profitability.” source ↗

    Management concedes it cannot forecast when the business turns profitable.

  • “Similarly, if our solutions detect attacks against a customer but the customer does not address the vulnerability, customers and the public may erroneously believe that our solutions were not effective.” source ↗

    The company admits customers may blame it for breaches it did not cause.

  • “For example, as free cash flow is negative, we will need to access cash reserves or other sources of capital for these investments.” source ↗

    Negative free cash flow is explicitly acknowledged as requiring outside capital.

  • “Additionally, if the incidence of cyberattacks were to decline, or enterprises or governments perceive that the general level of cyberattacks has declined, our ability to attract new customers and expand sales of our solutions to existing customers could be adversely affected.” source ↗

    A declining incidence of cyberattacks would itself be a business risk.

  • “Accordingly, the effect of downturns or upturns in new sales and potential changes in our rate of renewals may not be fully reflected in our results of operations until future periods.” source ↗

    The subscription model delays the visibility of any business deterioration.

  • “many of our employees have become, or will soon become, vested in a substantial amount of equity awards, which may give them a substantial amount of personal wealth. This may make it more difficult for us to retain and motivate these employees” source ↗

    A wealth effect from vested equity is disclosed as a retention risk.

  • “In 2018, Singapore introduced what is believed to be the world's first cybersecurity licensing requirement, mandating that providers of specific types of incident response services receive a government license before providing such services.” source ↗

    Direct regulation of the cybersecurity industry itself is emerging.

What this one teaches


  • A meticulously specific risk factor is not a hedge — it is a forecast. CrowdStrike's warning that customers 'have a low tolerance for interruptions of any duration' described the July 2024 outage far better than the generic detection-miss framing that surrounded it.
  • The competitors named in an S-1 are rarely the ones that matter five years later. Every named rival (McAfee, Symantec, Cylance, Carbon Black, FireEye) was dismantled or absorbed, while the eventual pressure came from Microsoft bundling — a name that barely featured in the competitive section.
  • 'No stated path to profitability' plus improving unit economics is a very different disclosure from 'no path.' The S-1's operating-leverage series (-172% → -111% → -55% operating margin; -123% → -26% FCF margin) was the real signal, and it extrapolated correctly.
  • Headline retention metrics disclosed at peak are mean-reverting by construction: 147% net retention on a 2,516-customer base fell to roughly 112% on a base 10x larger. Investors should model the decay, not the snapshot — the business can still compound enormously while the ratio deteriorates.

The paper trail


  1. 2019-05-14 S-1 filing index ↗ document ↗
  2. 2019-05-29 S-1/A filing index ↗ document ↗
  3. 2019-06-06 S-1/A filing index ↗ document ↗
  4. 2019-06-13 424B4 filing index ↗ document ↗

Filed as CrowdStrike Holdings, Inc.. All documents are public domain, served by SEC EDGAR.