Good day, everyone. Welcome to the Qualys second quarter 2016 investors conference call. This call is being recorded. At this time, all participants are in a listen-only mode. Later, we will conduct a question-and-answer session. Instructions for asking a question will be given at that time. I would now like to turn the call over to Melissa Fisher, Chief Financial Officer. Please go ahead, ma'am.
Thank you, Catherine. I would like to welcome everyone and take the opportunity to introduce Joo Mi Kim, our new Vice President of FP&A and IR. Joo Mi was previously an investment banker. Then worked at software companies in the Valley, including Anaplan. We are delighted to have her.
Thank you, Melissa. We would like to remind you that during this call, we expect to make forward-looking statements within the meaning of the federal securities laws. Forward-looking statements in this presentation include, are not limited to, the following. Statements related to our business and financial performance and expectations for future periods, including the rate of growth of our business. Our expectations regarding capital expenditures, including investments in our cloud infrastructure and the intended uses and benefits of those expenditures. Trends related to the diversification of our revenue base. Our ability to sell additional solutions to our customer base and the strength of demand for those solutions. Our plans regarding the development of our technology and its expected timing. Our expectations regarding the capabilities of our platforms and solutions.
The anticipated needs of our customers, our strategy, the scalability of our strategy, our ability to execute our strategy, and our expectations regarding our market position. The expansion of our platform and our delivery of new solutions. The expansion of our partnerships and the related benefits of those partnerships. Our ability to effectively manage our costs. Our expectations for currency exchange rates. Our plans to pursue arrangements with MSSP, which are multiyear contracts at fixed prices. Finally, our expectations for the number of weighted average diluted shares outstanding and effective GAAP and non-GAAP income tax rates for the third quarter and full year 2016. Our expectations and beliefs regarding these matters may not materialize. Actual results in future periods are subject to risks and uncertainties that could cause actual results to differ materially from those projected.
These risks include those set forth in the press release that we issued earlier today, as well as those more fully described in our filings with the Securities and Exchange Commission, including our latest Form 10-Q and 10-K. The forward-looking statements in this presentation are based on information available to us as of today, and we disclaim any obligation to update any forward-looking statements except as required by law. We also remind you that this call will include a discussion of GAAP and non-GAAP financial measures. The non-GAAP financial measures are not intended to be considered in isolation or as a substitute for results prepared in accordance with GAAP. A discussion of why we discuss non-GAAP financial measures and a reconciliation of the non-GAAP financial measures discussed on this call to the most directly comparable GAAP financial measures are included in our earnings press release issued earlier today.
Joining me for today's call are Philippe Courtot, our Chairman, President, and CEO, and Melissa Fisher, our CFO. Philippe?
Thank you, Joo Mi. Welcome to all of you. We're pleased to have delivered another excellent quarter. At $48.5 million, our revenues was up 21.5% year-over-year. This was above our guidance of $47.6 million-$48.3 million. As we're expanding our footprint with current customers as well as landing new customers, this is driving our confidence to raise our outlook for the year. Specifically, we are raising the bottom of our revenue guidance so that our new revenue range is now $197.1 million-$198.6 million. Similarly, we are moving up the bottom of our GAAP and non-GAAP EPS range. Our cloud platform now consolidates 10 enterprise-strength security solutions, giving customers unprecedented visibility and intelligence about all of their global IT assets, whether they reside on-premise, in the cloud, or at endpoints, and also drastically reducing their total cost of ownership TCO.
We're seeing tremendous adoption of our disruptive Cloud Agents, and during the second quarter, we achieved a remarkable milestone as we have now deployed over 1 million agents in our customers' environment, exceeding even our own very high expectations. Our second quarter results continue to show that we can, in fact, drive both strong revenue growth and top-tier profits. This is a function of our ability to deliver a steady stream of new offerings that we can sell very efficiently into our installed base, leveraging the cloud platform we have built over time. We're seeing increased uptake of our new solution, both on initial contracts and in upsell scenarios. This is underscored by the fact that the percentage of our enterprise customers who have three or more of our offerings has doubled versus three years ago, from 11% in Q2 2013 to 21% this quarter.
Not surprisingly, this drives larger contract size as upsells can be several multiples larger than the core VM engagements. The average deal size booked in the quarter increased by 18% from a year ago. We are now definitively in the right place at the right time, and to capture the opportunity, we have been reinforcing our sales organization. We have both grown our enterprise sales force and strengthened sales management by promoting from within and attracting great new talent as well. At the end of Q2 2016, we had 18 regional sales leaders covering more than 100 countries, and the sales management team has on average five years of tenure with Qualys. We operate, in fact, in a healthy demand environment and believe that we are a prime beneficiary of the undisputable trend, I should add, to cloud computing.
We feel confident that this will help us sustain and even improve our growth rates in the coming years. There's an increasing need among customers to leverage cloud-based security solutions as they are now accelerating the migration of their IT infrastructure to cloud solutions. The reality is that in order for companies to prevent breaches rather than react after the fact, they must leverage enormous amount of data, and there is simply no way to do this cost-effectively with on-premise enterprise software. These views are shaped not just by the data itself, but also by the significant amount of time I personally spend with clients. I recently met with a CIO of a major European financial institution and a Qualys customer. He echoed that vulnerability management is increasing in importance for his company.
The regulation they must abide by require that they have visibility on all IT assets, not just the perimeter, and that they be able to demonstrate this. On-premise enterprise software solutions become cost-prohibitive at this scale. He sees no choice but to move to a cloud-based IT model to improve the agility and reduce the cost of his IT infrastructure. He shared that his goal is to have 80% of his IT infrastructure in the cloud three years from now. As all companies must do more with less, they are looking to consolidate vendors, and we are gratified to hear from many of our customers that they would like to do more with us. We're pleased to be chosen for an increasing number of standardization arrangements, both with customers and with partners.
These validations are powerful and position us as a disruptive force in the security and compliance industry. Being a strategic vendor to our customers is a function of the current capabilities of our solution, as well as their confidence that they will continue to innovate and expand our features and functionalities. We have released several exciting innovations in the second quarter, namely Qualys Threat PROTECT, that became generally available in the quarter. This helps customers prioritize vulnerabilities based on a number of key threat indicators. At the Gartner Summit, we announced a groundbreaking new form factor to extend our private cloud security and compliance to medium-sized companies, delivering our entire cloud platform in a 1U format, totally remotely managed and self-updating.
This now allows us to address those companies who need to retain data on-premise or within local geographies, but do not have a big enough IT infrastructure to adopt our larger Private Cloud Platform. We have now 30 Private Cloud Platform deployed over the planet. This new Private Cloud Appliance, as we call it, supports both scanners and Cloud Agents and includes a comprehensive, integrated suite of Qualys apps for automating asset discovery, security assessment, and compliance management. Our Security Assessment Questionnaire 2.0 was also released in the second quarter. This is a cloud-based solution that orchestrates IT audits with automated validation to dramatically simplify third-party and vendor risk assessment. We achieved the first level of FedRAMP certification in the quarter. We expect to have the full FedRAMP certification this current quarter.
This offers federal agencies a path to quickly adopt our Qualys Cloud Platform for continuous security and compliance to provide them with a continuous view of their security. Subsequent to the end of the second quarter, we announced the expansion of the Qualys Cloud-based Security Compliance Platform to support Microsoft Azure with a new Azure-certified virtual scanner appliance. This enables organizations to assess the security and compliance posture of their Azure environment from the Qualys console. Each of these new offerings brings key solutions to market that were previously not served extensively or at all. Let me finally emphasize that we're not only taking share from our legacy competitors, but we're also entering new markets, enabling our customers to consolidate their spending with us and delivering better performance as a function of our solution being integrated and accessible through a single platform. Thank you
Thanks, Philippe. Good afternoon. Our strong second quarter performance reflects the recognition by our customers of the operational and financial value of our Cloud-based Security Platform, which provides a holistic view of our customers' assets and their vulnerabilities. Total revenues in the second quarter were $48.5 million, which represents 21.5% growth over the second quarter of 2015. As we discussed last quarter, we signed an attractive new arrangement with one of our MSSPs, which resulted in additional revenue being recognized in 2016 for the same customers. In the second quarter, this represented a little over $1 million of revenues, slightly higher than in Q1. In contrast, FX again muted second quarter revenue. Excluding the impact of the MSSP and FX, our year-over-year revenue growth rate was still a robust 20.4%. The U.S. represented 71% of Q2 revenues or the same as the year ago period.
Some of our international clients pay us in U.S. dollars. Our revenue exposure to foreign currencies was only around 17% of total Q2 revenues. Our revenue plus the change in our current deferred revenue balance grew 29% year-over-year. I highlight this because I recognize it's a metric investors track as a proxy for current bookings. However, I would like to point out that this calculation will not always mirror our current bookings due to the timing of the actual invoicing as well as impacts of items like FX. This quarter, it does reflect our strong performance. However, please note that it was positively impacted by the large slipped renewals from Q1 that we mentioned in our last call, as well as being negatively impacted by the MSSP contract and FX.
Said another way, when I compare our historical quarterly bookings growth rate to the historical year-over-year growth of revenue plus the change in current deferred revenue, they are not always in line. Our current deferred revenue balance was $104 million as of June 30th, 2016, 19% greater than our balance at June 30th, 2015. As we have discussed, the change in the MSSP contract reduces our current deferred revenue balance account because it's billed on a quarterly basis. Excluding the impact from the MSSP contract as well as FX, our current deferred revenue balance would have grown 21% year-over-year. Last quarter, we discussed that our existing disclosure of metrics may not be the best reflection of the positive trends in our business. We have evolved from a single-product company to a multi-product platform business with 10 solutions that have varying pricing, growth rates, and release dates.
We are adding new capabilities, extending the breadth of our solutions. We have enhanced our core VM offerings through new solutions as well. Through the end of 2016, we will maintain the current disclosures. We expect to roll out new metrics at our upcoming Analyst Day on November 17th that more properly reflects how our business is trending. On the existing basis, our vulnerability management solutions remain strong, thus continuing to represent 79% of second quarter revenues, in line with the results in the second quarter of 2015. Our last 12 months bookings growth rate for policy compliance and web application scanning was 26% year-over-year. Note that this figure does not include newer solutions like our Cloud Agent used for vulnerability management, our PCP, and ThreatPROTECT.
As an initial step toward our new metrics, Philippe shared with you the percentage of our enterprise customers who have purchased three or more Qualys products. While we sell our platform cost-effectively to both small customers of 50 employees as well as to large enterprises, we expect to see additional solution uptake more pronounced in our enterprise customer base. Our prior disclosure was the percentage of total customers with two or more products, including PCI. This figure was 63% in Q2, up from 60% a year ago. Incidentally, we are adding an updated investor deck to our investor relations website today to increase the clarity of our message. Before moving to profit and loss items, I would like to point out that unless otherwise specified, all of the expense and profitability metrics I will be discussing on this call are non-GAAP results.
Our non-GAAP metrics exclude stock-based compensation and non-recurring items. A full reconciliation of all GAAP to non-GAAP measures is provided in the financial tables of the press release issued earlier today and is available on the investor section of our website. Gross profit increased 21% year-over-year to $38.8 million in the second quarter of 2016. Gross margin was 80%, equal with second quarter last year. Our strong margins are a testament to the scalable operational model of Qualys and are higher than other comparable security and SaaS companies. Our platform enables us to easily launch new mission-critical capabilities that will plug and play with other Qualys offerings and are therefore highly cost-effective to sell. In fact, our 2015 revenue per sales and marketing head is over $1 million as compared to a median of approximately $540,000 for comparable security and SaaS companies.
One driver is that our cloud-based platform enables a try and buy at generating sales at a lower cost than on-premise software companies. We're continuing to leverage low-cost geos with a percentage of our customer support, operations, and R&D headcount in India having increased to 36% in 2015 from 15% in 2013. By having a strong operation there, we can innovate 24 by seven, which accelerates our ability to develop solutions for our customers. We are taking advantage of our highly profitable model to invest for growth as we see multiple levers to drive additional revenues. Operating expenses increased by 21% year-over-year to $27 million, in line with our stated goal to increase our investments in terms of headcount, systems, and other services to scale the business.
We added 92 people in the first half of 2016, compared to 53 people in the first half of 2015. Research and development expense increased to $7.7 million or 26% year-over-year, primarily due to higher headcount. While we are adding personnel there, it is important to note that we have a highly efficient R&D organization with an average annualized personnel expense per employee of approximately $110,000 as of Q2. Our R&D organization has delivered many new products over the last 12 months, including the Cloud Agent platform, the ThreatPROTECT, the Security Assessment Questionnaire 2.0, and the 1U PCP appliance, as well as new feature functionality such as Elasticsearch and AssetView integration with ServiceNow. Sales and marketing expense increased to $13.1 million, 11% year-over-year, primarily due to higher sales headcount, as well as costs related to our salesforce.com implementation, offset by somewhat lower expense in marketing.
As Philippe mentioned, we've been growing our enterprise sales force and are proud of our high productivity. G&A increased to $6.3 million, 41% year-over-year, largely due to higher headcount and legal, accounting, and consulting fees related to our increased scale worldwide. Due to our strong revenue growth, adjusted EBITDA for the second quarter of 2016 increased by 20% to $15.7 million, compared to $13.1 million in the second quarter of 2015. The MSSP contract change had a positive effect since revenues were higher, but excluding this impact, adjusted EBITDA would still have increased over the second quarter of 2015. Adjusted EBITDA margin in the second quarter of 2016 was 32% as compared to 33% in the second quarter of 2015. Moving on now to earnings per share. For the second quarter of 2016, GAAP EPS was $0.09 per diluted share, same as the second quarter of 2015.
Non-GAAP EPS was $0.20 per diluted share in the second quarter of 2016, up from $0.16 in the second quarter of 2015. Our Q2 non-GAAP expenses, net income and EPS exclude a one-time tax-related expense. I'd note that non-recurring items included in non-GAAP expenses, net income and EPS over the last couple of years have been immaterial. Net cash from operations in the second quarter of 2016 increased by 12% to $17.3 million, compared to $15.5 million in the same period in 2015. Free cash flow generated in the second quarter of 2016 was $12.7 million, compared to $11.3 million in the comparable period of 2015. In the second quarter of 2016, capital expenditures were $4.8 million, compared to $4.3 million in the second quarter of 2015. In addition to this, we front-loaded approximately $7 million of CapEx that is scheduled to be paid later in the year.
Of the $7 million, $5 million was related to the early renewal of a license arrangement as we were able to lock in an attractive rate on database software for the next several years. This was CapEx that otherwise would have been spent in 2017 and does not represent a change in our business model. In the third quarter of 2016, we expect capital expenditures to be in the range of $5.5 million-$6.5 million, excluding the previously mentioned $7 million incurred in Q2. We expect to spend only three and a half million to four and a half million in capital expenditures for Q4, offsetting the increased Q2 and Q3 spend. Excluding the early license renewal, we are projecting capital expenditures of $20 million-$22 million in total for 2016. Turning to our guidance.
Starting with revenues for the third quarter of 2016, we expect revenues to be in the range of $50.3 million-$51 million.
For the full year 2016, we are raising the bottom end of our guidance for revenues, bringing our current guidance to a range of $197.1 million-$198.6 million. As to earnings per share guidance, we expect GAAP EPS for the third quarter of 2016 to be in the range of $0.08-$0.10 per diluted share, while non-GAAP EPS is expected to be in the range of $0.17-$0.19 per diluted share. For the full year of 2016, we are raising the bottom end of our guidance for both GAAP and non-GAAP EPS. Our current guidance for GAAP EPS is now $0.37-$0.41, and for non-GAAP EPS, $0.75-$0.79. We expect our operating expenses to sequentially increase in Q3 and Q4.
We are continuing to invest in our business as we scale for the rollout of additional solutions to our platform because we have a highly profitable operational model. Our third quarter EPS estimates are based on approximately 38.8 million weighted average diluted shares outstanding. Our full year 2016 EPS estimates are based on approximately 38.9 million shares outstanding. For the third quarter and full year 2016, we have used an expected effective GAAP tax rate of 38% and an expected effective non-GAAP tax rate of 36%. I'm thrilled to be at Qualys. I'm now almost 100 days into my tenure here, and I've gained significant visibility into the growth opportunities for our business and a scalable operational model. With that, Philippe and I would be happy to answer any of your questions.
Thank you, ladies and gentlemen. If you have a question at this time, please press the star, then the one key on your touch-tone telephone. If your question has been answered or you wish to remove yourself from the queue, please press the pound key. Please limit your questions to one and one follow-up only. Thank you. Our first question comes from Sidd Panigrahi with Credit Suisse. Your line is open.
Hi. Thanks for taking my question. I just wanted to focus on the VM market. You talked about 10% growth last quarter. I'm just wondering what sort of growth rate you saw this quarter and what sort of competitive landscape. Are you seeing any kind of legacy displacement in the market that's driving growth at this point?
No. We didn't speak of 10% growth. We're saying that our VM marketplace that we're growing at around 20%, 21% growth. This is what we said. As far as the competitive landscape, we have essentially in our space that has what I call the two last man standing, essentially Tenable, which is a private company, and Rapid7, who's a public company. We essentially have an extremely strong position with a large enterprise. Rapid7, we see them gaining more in the mid-market. Tenable is strong in government and with consultants, essentially. They're all trying, of course, to go and attack our large customer base. I think we remain today the company which has really, truly a cloud platform, which is a huge advantage. We also deliver new services totally consolidated with our platform, that increase the barrier to entry significantly against Qualys.
To speak about the VM marketplace, as I mentioned during the call, is that we see vulnerability management becoming as a significant core security application that company must absolutely adopt. This is relatively new, this is because you cannot secure what you don't know. Everything is interconnected with everything. You need to have a global view of all of your IT assets, then you need to ensure that they are not vulnerable to attacks, then you need to prioritize the remediation, remediate as fast as you can today. It's a question of time. Prioritize the remediation and improve your remediation capabilities.
As a follow-up, you talked about Cloud Agent deployment around 1 million already, you also released ThreatPROTECT. I'm wondering what sort of early feedback you have got on ThreatPROTECT and what sort of adoption you're expecting.
Yeah. We're expecting a very strong adoption of ThreatPROTECT. We have essentially that solution went GA about a month ago. We already have quite a few orders, a big demand for that. It's a very natural extension of our platform. We replace here either standalone solution that we're taking the data out of Qualys and then correlating that data with threat information and/or company taking the Qualys data, putting that into Splunk, and then putting threat information into Splunk and doing that application in Splunk. Obviously having that native on Qualys is significantly easier and better for our customers. We see all our customers which have already used these kind of two solutions that I mentioned are looking at migrating to Qualys. Of course, it becomes also a very big differentiator when we compete for new business.
Thank you. Our next question comes from Gur Talpaz with Stifel. Your line is open.
Great. Thanks for taking my question. I wanted to talk about Cloud Agent adoption. Philippe, you noted over 1 million endpoints, and that's a pretty big metric given how relatively new the product is. Maybe you could talk about what's driving that adoption, what's driving that strength, and maybe walk us through what a typical Cloud Agent deal looks like in terms of penetration of a customer.
Yes. In fact, this doesn't really surprise us, where there are a lot of people saying, "Oh, it's so difficult to put agent," et cetera. The argument I was making then was that what our Cloud Agent does first is to essentially make the vulnerability management application significantly easier to deploy and manage because you don't need credentials now, you don't need scanning windows, and you have real time. This is quite significant. We see existing customers adding the Cloud Agent to some of these IPs that they were scanning, so adding on the device, of course. Also, interestingly enough, it allows us now to move into endpoints. We see also customers adopting the agent for their endpoints. Furthermore, unlike anybody, our agent also, they go into the cloud.
Our agent has that unique ability to go to on-premise, on servers, et cetera, on endpoints, as well as on cloud environment. We have just announced, by the way, recently that we have worked with Microsoft, and now we are in the process of finishing the total integration of our agent with the Microsoft Azure platform, so customers could directly from the Microsoft Security Center immediately have the agent available at a click of a button. It's a significant integration, and we're working as well with all these other cloud vendors to do exactly that same thing. This is significant adoption. Of course, it does now start to do the same thing for the policy compliance.
Let me remind that we see the agent is really a new platform or an extension of our cloud platform, and this is going to allow us to deliver, in a relatively short period of time, additional functionalities that all of our customers are asking, which are the file integrity monitoring capabilities, the detection of IOCs, the patch management capabilities, and also we're working on the digital certificate as well. This is absolutely a no-brainer for our customers, essentially.
That's great color, Philippe. One last question. In your script, you noted achieving FedRAMP compliance. In the past, you talked about the federal opportunity. Can you talk about the pipeline there now that you've achieved a level of compliance in that arena? Do you see it building up? Is it a real opportunity sort of beginning to play out?
Definitively, I think we're at the right time, at the right place now with Federal. As you know, everything in Federal takes time. We're not expecting to see any kind of significant revenue this year. I think we're very well positioned for next year because, again, as you see, the Federal is absolutely crippled with data breaches. The reason is because they are using all these enterprise security solutions. They don't integrate their massive networks. Enterprise security software just doesn't cut it. You need to have that scalability that our cloud platform provides, so you can identify, again, all of your global IT assets, their vulnerabilities, their security posture. In the past, the Federal didn't want us because we're eliminating a lot of because of the complexity of the procurement cycles, et cetera. Being FedRAMP is really the key for us.
I think we're very confident that next year, hope to start to see really business coming from the Federal government.
Thank you. Our next question comes from Craig Nankervis with First Analysis. Your line is open.
Thanks. Good afternoon. Nice quarter, folks. Philippe, you mentioned that scenario over in Europe someplace about the regulations or visibility into all IT assets. Are you pursuing any special initiative to really capitalize that over there in any part of the market? Seems like it would be really something that could add to your growth.
That's a very good point there, Craig Nankervis, because in Europe, our deal size has been historically much lower than in the U.S. The reason, because the European companies were much slower at adopting that cloud-based vulnerability management solution that we have for the internal network. The bank that I've mentioned to you before was, in fact, a customer since 2002, very happy with Qualys, but it's only now that they're looking at essentially deploying us on the inside. The regulation is really a very big driver of that because the regulation in Europe is really becoming you could see a change from the regulator to try to reverse the burden of proof. You have to prove now that you have taken everything, you have done everything you could have done to secure your network.
That's really tough. The fact that today we have a very strong partnership with companies like Orange Business Services, Airbus CyberSecurity, Siemens, we have a lot of very big partners. We can deliver also private clouds locally. All these issues about where does my data reside, and certainly not in the U.S., they don't want that anymore. We have solved all of these problems. I think Europe is ripe for us to see bigger deals from our existing customers, and we have a large customer base in Europe. As well as our competition there is not very strong. Really being capable of becoming a major player in Europe as well.
Are you adding more sales heads there by chance to-
We have already made a huge. In fact, what is interesting is that we don't have a very good productivity in Europe as compared to the U.S. because, again, what I told you about the deal size is much lower, but we are very well staffed in Europe. Already, as I mentioned, we have five regional VPs in the U.S., and we have now today about 14 outside of the U.S. We have a significant already presence established with long-term customers, we're very strong in Europe. It's just a question about the deal size, which is now starting to move into our favor.
Can you also just review where your data center locations are over there now with, does Brexit have any impact on the services you offer?
No, absolutely. Very good question again. Historically, we had a data center in Geneva, and now we're adding another data center in Amsterdam, and the reason is because, today with this new regulation, Switzerland is not part of the EU. That the Switzerland, which was the place of peace, is not anymore the place of peace, if I may say so. You've got to have your data in the EU community, which is what we're doing now. In addition to that, we have company like Deutsche Telekom or T-Mobile, which they have their own private cloud. We have Orange Business Services, which has also a private cloud, Airbus CyberSecurity, a private cloud, Siemens, a private cloud. We're also that ability of really delivering private cloud very easily.
All of these regulation works in our favor because we keep the power of our cloud model, but now we can really deliver it on premise or within a local geography, like we do Telekom in Dubai, Saudi Telecom in the kingdom, and others. Okay.
Thank you. Our next question comes from Matt Hedberg with RBC Capital Markets. Your line is open.
Thanks for taking my questions. Philippe, in your prepared remarks, you talked about your expectations for improving growth rates longer term. I know you guys have 10 products, but I'm curious, outside of sort of your core VM, WAF, PCI, and policy compliance, if you could only pick one, which of these additional products do you think has the highest potential to become really a major contributor to future growth?
The major contributor to future growth with no question asked is the Cloud Agent platform for the reasons that I mentioned earlier, all these additional revenue streams that we're going to generate. Relatively early in the year for next year with file integrity monitoring, detection of indication of compromises, the patch management, the digital certificates. This is something we see coming very strongly. We have interesting additional products like ThreatPROTECT, which are really, we charge 30% of the VM subscription to our customers to have the benefits of ThreatPROTECT. That's a nice little bump on a huge VM customer base. We have also our Security Assessment Questionnaires that we see also adding to the policy compliance application. These are things that currently today are in production and doing very well. That's what we see.
Great. Maybe one for Melissa. You guys had a nice earnings beat this quarter, and I know you did raise the low end of your full-year guide slightly, but I'm curious why didn't it go even higher? Is this a reflection of additional hiring or conservatism? Just want to make sure I understand sort of the thought process around the full-year earnings guide.
Yeah. No, great question, Matt. It's a couple of factors. As we've mentioned, we have been increasing hiring, so to the extent we do that within a quarter, that is one factor that contributes to the sequential increase in expenses as well as there is additional investment in these areas like headcount that we're continuing to make.
Thank you. Our next question comes from Michael Kim with Imperial Capital. Your line is open.
Hi, good afternoon, guys. Can you just talk a little about pricing trends and specifically on continuous monitoring and ThreatPROTECT? I think you did mention just possibly 30% lift of the current VM subscription and I think last quarter for CM, maybe something like a 20% lift. Are you still doing some price discovery and how is that holding?
No, the price is holding fine. I think we're just absolutely, in fact, we received praise from our customers, now we got enough of them, so it's just not one or two. They said they were very happy with our pricing. They thought it was a fair price, no question asked. We had, in fact, everything we do, we always try to engage customers before, so we don't come and suddenly surprise our customers. We work with them on the new product, on the new pricing. We try to really understand what they are expecting. That was really, we're very confident with the pricing.
With the upsells getting larger, are you seeing any change in average contract length and how might that adjust the pricing?
We haven't seen any change in average contract length per se. What we've talked about in the past is that when we do have larger deals, larger deals take longer to close because it's a more involved procurement process and more approvals required. We haven't seen much movement today now.
On the contract length specifically, we see more and more for large customers, they want multi-year contract. We are doing more three-year contracts at the request of our customers. That has been a trend, we're doing.
It hasn't been enough to move the needle to date.
It doesn't change the revenues. It doesn't change at all our booking either, because we annualize everything.
Right.
We have some prepaid deal, which sometimes could, of course, impact the current deferred. These one are relatively rare as being prepaid. We have a few of those.
Thank you. Our next question comes from Jack Andrews with D.A. Davidson. Your line is open.
Hi, good afternoon. Thanks for taking my question. Philippe, you introduced a slew of new products earlier in the year, as we're sitting here slightly past, I guess, the halfway point of 2016, can you update us just in general on your thought process for additional products? Are there any particular market adjacencies, perhaps, that look attractive to you?
First of all, they were not early in the year that much, with the exception of the Cloud Agent. Threat PROTECT was very recent. Our security assessment questionnaires was very recent, in fact. This being said, we are expecting today, essentially with the new services that we're planning to deliver, we're looking at having them as a showcase at our user conference in October. We probably will showcase them our Analyst Day as well in November. We see them as generating revenues early next year, starting early in the year. In term of market adjacency, we're just continuing to essentially expand really naturally. You look at ThreatPROTECT , this is adds to VM. There's a very interesting market that we believe we can really make a very big difference. In fact, two markets. One is the asset discovery.
We believe that today we have absolutely the best technology today to do asset discovery and inventory, then synchronize like we're doing today now with ServiceNow. That's almost like more of an IT, if you prefer, market. Our view here is that we can bring security and compliance and IT security and compliance into one single solution. We're starting to really compete very effectively against Tanium, which you could consider as an additional market. There is we're looking at the digital certificates. We think we have a very good solution. We already have half of the solution for digital certificates in the sense that we can discover all of your digital certificates, then we can analyze where they're coming from, when they're going to expire.
The only thing which we're missing today to really provide the full solution, which we're working on as we speak, which is the ability to update or manage these digital certificates. We're not far from having also that solution. That's the kind of really adjacent market as well.
Thanks. I appreciate that. Just as a quick follow-up, could you give us an update in terms of just your senior management team? Are there any meaningful roles that you're still looking to fill at this point?
Yeah, we're always expanding our management team. We're starting to really looking very seriously at doing some acquisitions, albeit very carefully, which is a way to increase the management. Currently, I'm looking at adding a Chief Security Officer. We're currently actively looking. We had our VP of worldwide sales, which went back with his previous company, and so that give me the opportunity to really look for somebody as well. These are essentially the two key position on the management level that we're looking at adding.
Thank you. Our next question comes Srini Nandury with Summit. Your line is open.
Right. Thank you for taking my call. This question is for Philippe. Philippe, I know your Cloud Agent that was initially for Windows, and last quarter, you released the products for Linux and macOS. Can you talk about whether these products are being deployed in the field, and can you talk about how the pricing for these new services are? Then I have a follow-up, please.
I'm not so sure that I understood the question. You're asking about the price for this Cloud Agent?
For the price as well as you launched a Linux version of your Cloud Agent and macOS earlier last quarter. I just wanted to understand how those products have been doing in the market and what your conversations have been. Yeah.
Okay. The Unix agent for Unix is essentially the big market for them is of course with companies which are using Unix servers as well as the cloud environment. The cloud environment are essentially Unix. We put that down. Very successful. It was in big demand. The Mac is much more for the endpoint, essentially. That's also strengthened our position and offering on the endpoint. All in all, today when I look at these agents, so there's a combination of adding to the existing VM that we're doing. We have as an average today with this Cloud Agent, We are in a above the, I would say, $5 per agent per year. It's got to be an interesting add-on to our business, and it's growing very well.
Okay.
Does that answer?
Yes. Just extending the Cloud Agent technology, it looks like it's a natural extension for endpoints for such as Android devices and iOS. You and I talked about this a while ago. Do you expect to release the Cloud Agents for handheld devices as well?
No.
Go ahead.
Yeah. No. The issue with the Android devices and iOS devices is that you cannot really put an agent, or let's say the agent that you can put can give you minimum, really minimum information. There's already a market with the MDM applications. For us, our strategy at the moment there is to essentially take the data from this MDM vendor to enrich the information that we have and put all of that into our cloud backend, rather than doing an MDM agent because it's already preoccupied. This being said, when and if Google and Apple open up their OS, we could put an agent, then we're ready for it. The challenge is not to build the agent. The challenge is really all the analysis. You have to build that to hundreds of millions of agents, if not billions of agents.
Currently today, one of the large cloud providers now deploying 2 million agents, of Qualys in the process of deploying this agent. That's a question of scale, and of course, that's a problem that we have solved. We're also working on providing an SDK for our agents so people could build the agent themselves, then we can provide all the processing, if you prefer, backend to do all what needs to be done with the data that the agents are bringing back. Does that make sense?
Ma'am, thank you. Our last question comes from Steve Ashley with Robert W. Baird. Your line is open.
Thank you very much. Philippe, I just want to ask a high-level question on the industry, and you kind of have a statesman of the industry and a big-picture view. There are rumors that McAfee might be for sale. There are rumors that FireEye might be for sale. There are rumors that Imperva might be for sale. We're seeing Symantec and Blue Coat merge. There seems to be at least the rumor of a lot of consolidation of some meaningful-sized businesses. What do you see going on in the industry, and why do you think this might be happening now? Thanks.
This is a fantastic question, Steve. I really appreciate it. In fact, yes, this is exactly what is happening. By the way, it's not surprising. This is something, by the way, that I predicted many years ago. I'm a little bit late.
Timing
on the timing. You look at what happened with the mainframe industry, going through the mini computer industry, which was more of a technological evolution, a totally new architecture came with the client server, now we're seeing the same thing happening with the cloud computing architecture. Today what is happening is like we saw in the mainframe, mini, et cetera, is the consolidation of the old industry, which is about to die. The question is how long it will take. The emergence of a new breed of company, which I strongly believe Qualys is one of them. Nothing new here. The only thing which is new is today, the very specific challenge that security has, which is very unique and it's becoming very clear. There was a discussion with Jeff Moss, in fact, this morning.
We're just at Black Hat now, with Jeff Moss, the founder of DEF CON and Black Hat, that this is exactly the same thing. Security today is a huge challenge because things are going so fast. You have the complexity has increased significantly. The speed at which the attacks are coming are absolutely incredibly fast. The bad guys now can detect vulnerabilities in your organization even before you can yourself do. They've already created an exploit, and you're attacked now in no time. How do you protect against that? You really have to change. This is where all these enterprise solutions are falling apart because they are too slow. They are too costly to manage. What do you do with all that data? They don't integrate with themselves.
There's absolutely a need for that new breed of solution, and we see that from our customers. I think the market is coming our way big time.
Great. Thank you. Thank you everyone for attending our Q2 earnings call. We look forward to seeing many of you next week at the Pacific Crest conference in Vail and the Credit Suisse Small and Mid Cap conference in New York in September. We will be holding an analyst investor day in New York on November 17th, and if you would like to attend our annual user conference as well, which will be in Las Vegas in October, please let us know. Thank you.
Ladies and gentlemen, thank you for participating in today's conference. This does conclude today's program. You may all disconnect, and everyone, have a great day.