Cellebrite Di Ltd.
A maker of digital forensics tools, Cellebrite builds software and hardware that law enforcement and government agencies use to unlock smartphones and pull out texts, call logs, and photos—even from damaged or encrypted devices. Founded in 1999 in Petah Tikva, Israel, it began as a consumer phone-shop gadget for moving contacts between different handsets. Its name blends "cellular" and "bright," a nod to those phone-shop roots before it became a go-to name in criminal investigations.
20-F · Fiscal year ended Dec 31, 2025 · SEC filing ↗
The original filing sections are available below.
We are exposed to market risk in the ordinary course of our business. Market risk represents the risk of loss that may impact our financial position due to adverse changes in financial market prices and rates. Our market risk exposure is primarily a result of fluctuations in for…
We are exposed to market risk in the ordinary course of our business. Market risk represents the risk of loss that may impact our financial position due to adverse changes in financial market prices and rates. Our market risk exposure is primarily a result of fluctuations in foreign currency exchange rates and interest rates and inflation. For information about the effects of currency and interest rate fluctuations and how we manage currency and interest risk, see “Part I, Item 5. Operating and Financial Review and Prospects—B. Liquidity and Capital Resources”. 156 Table of Content
Read original filing text →A. [Reserved] B. Capitalization and Indebtedness Not applicable. 7 Table of Content C. Reasons for the Offer and Use of Proceeds Not applicable. D. Risk Factors An investment in our securities involves a high degree of risk. You should carefully consider the risks described belo…
A. [Reserved] B. Capitalization and Indebtedness Not applicable. 7 Table of Content C. Reasons for the Offer and Use of Proceeds Not applicable. D. Risk Factors An investment in our securities involves a high degree of risk. You should carefully consider the risks described below before making an investment decision. Our business, prospects, financial condition, or operating results could be harmed by any of these risks, as well as other risks not known to us or that we consider immaterial as of the date of this Annual Report. The trading price of our securities could decline due to any of these risks, and, as a result, you may lose all or part of your investment. Risks Related to Cellebrite’s Business and Industry If we do not continue to develop new and technologically advanced solutions and enhance our products, our future revenue, financial and operating results may be adversely affected. We offer a comprehensive suite of AI-powered digital investigative and intelligence solutions that includes a variety of software offerings designed to help our customers, access, collect, review, analyze and manage digital investigative data derived from digital sources, including mobile phones in particular, that are manufactured or produced by a variety of original equipment manufacturers (“OEMs”) as well as the software applications installed on such devices. Mobile phone and other digital device OEMs and other software manufacturers are continuously changing their products, and upgrading their operating systems and software applications. The access and extraction capabilities that we offer are patched and blocked by OEMs from time to time as they upgrade or improve the security and encryption on their digital devices. To date, we have been able to upgrade, improve and evolve our products and technology through a combination of internal development and third-party partnerships to address the changes made by OEMs, although the speed at which we are able to deliver production-ready updates and improvements can vary greatly. If we are unable to deliver these capabilities via our solutions or fail to do so in a timely manner, we may not be able to provide our customers with the ability to lawfully access certain investigative or forensic data and, as such, our customers’ ability to carry out their mission may be degraded. In addition, there is no assurance that we can generally meet the evolving needs of our customers by designing and developing new solutions and upgrades to our existing software and/or hardware solutions that address their needs. If any of these circumstances materialize, the perception of the value of our products may decline, and our future revenue, and our financial and operating results, may be adversely affected. If law enforcement and other government agencies do not continue to purchase, accept and use our solutions, our revenue will be adversely affected. Sales to public safety agencies, including law enforcement, defense and intelligence agencies, accounted for more than 90% of our revenue in 2023, 2024 and 2025. At any point, as a result of external factors outside of our control, irrespective of our products’ performance, law enforcement and governments agencies may elect to no longer purchase our solutions. The key trends affecting the digital investigations market include, among other things, growth in the volume of digital data, increases in data complexity and sophistication, inefficient operations resulting from manual, time-consuming and/or siloed activities, and increased public scrutiny on the way criminal investigations are conducted, all of which are compounded by strained headcount and financial resources. If we are unable to meet these evolving needs, law enforcement and other government agencies may not continue to purchase, accept and use our solutions, and our revenue and financial condition will be adversely affected. Our revenue, financial and operating results may also be impacted by regulatory developments that diminish the need for certain products or by changes in organizational structure within the public 8 Table of Content sector. For example, certain governments and regulators have proposed adopting alternate measures to ensure access to mobile devices for law enforcement. Among other things, governments have tried in the past to enforce “back door” arrangements on OEM and device manufacturers. One instance of this is a 2025 UK demand that Apple provide such “back door” access and the subsequent litigation involving Apple’s removal of advanced data protection (ADP) capabilities from the UK market. Changes in organization structure can complicate decision-making processes, by budget re-allocations or funding cuts which may be introduced by new administrations or changes in political focus or by a slowdown in the pace of adoption of investigation and justice acceleration related technologies in the public sector. Real or perceived errors, failures, defects or bugs in our solutions could adversely affect our results of operations, financial results, growth prospects and reputation. Because we offer software solutions, undetected errors, defects, failures or bugs may occur, especially when solutions or capabilities are first introduced. Errors, failures, or bugs may not be found in new software or releases until after they are implemented, and this could adversely affect our reputation and our customers’ willingness to buy solutions from us, and adversely affect market acceptance or perception of our solutions. Many of our customers, especially those in law enforcement, use our solutions in applications that are of public interest or critical to their businesses or missions and may thus have a low risk tolerance for defects in our solutions. Errors or delays in releasing software updates or allegations of unsatisfactory performance or errors, defects or failures in released software could cause us, to lose sales opportunities, increase our service costs, incur substantial software redesigning costs, lose customers or subject us to liability for damages and divert our resources from other tasks, any one of which could materially and adversely affect our business, results of operations and financial condition. An error, failure or bug in any of our solutions used by our law enforcement customers could lead to interference with the administration of justice, for example by corrupting digital evidence and even rendering them inadmissible. Real or perceived errors, failures, or bugs in our solutions, or dissatisfaction with our solutions and outcomes, could result in customer terminations or non-renewals. In such an event, we may be required, or we may choose, for customer relations or other reasons, to expend additional resources in order to help correct any such errors, failures, or bugs. We license technology from third parties, and our inability to maintain those licenses could harm our business. In addition to capabilities that we directly develop and incorporate into our solutions, we have incorporated, and may in the future incorporate, technology that we license from third parties, including certain intellectual property and software capabilities that facilitate access to certain devices. If we are unable to license technology from third parties, we may need to acquire or develop alternative technology, which we may be unable to do in a commercially feasible manner and may require us to use alternative technology which is of lower quality or performance standards. This could limit or delay our ability to offer new or competitive solutions and increase our costs. In addition, our use of third-party technology may also enable customers to engage directly with such technology providers or with other developers, potentially bypassing our solutions. As a result, our margins, market share, and results of operations could be significantly harmed. 9 Table of Content A failure to maintain sales and marketing personnel productivity or hire, integrate and retain additional sales and marketing personnel has in the past and could in the future adversely affect our results of operations and growth prospects. Our business requires intensive sales and marketing activities on a constant basis. Our go-to-market strategy is aimed primarily at expanding the scope of our relationships with existing customers and attracting a larger number of law enforcement customers to use more of our solutions. Our sales and marketing personnel are essential to this effort. We require personnel with expertise in government contracting at the federal, state and local levels in a variety of countries, and expertise in the private sector, and with sufficient technological literacy to discuss our solutions’ features. There is a limited number of individuals with this experience and competition for them is intense. Furthermore, once hired, it typically takes up to six or more months before a new sales force member is fully trained and operating at a level that meets our expectations, and training may take even longer when working remotely. While we invest significant time and resources in training new members of our sales force, we may not be able to achieve our target performance levels with new sales personnel, whether due to larger number of new hires, or lack of experience training sales personnel to operate in new jurisdictions or because of remote hiring and training process, among other reasons. Our failure to hire a sufficient number of qualified individuals, to successfully integrate new sales force members within the time periods we expect, and to contain sales force attrition rates may materially impact our financial and operational results as well as the growth of our business. We face intense competition, including as a result of consolidation in our industry, which could increase the pricing pressure we face and cause us to lose market share, which would adversely affect our business, financial condition, and results of operations The markets for our solutions are highly competitive and are subject to rapid technological change and other pressures created by changes in our industry. We face varying levels of competition across our solution offerings. Many of our current and potential competitors are larger and/or may have substantially greater resources than we have and expect to have in the future. They may also be able to devote greater resources to the development of their current and future technologies or the promotion of their offerings or offer lower prices. Our current and potential competitors may also establish cooperative or strategic relationships among themselves or with third parties that may further enhance their brand and reputation, resources and offerings. In recent years, there have been mergers and acquisitions within our industry by our competitors, and further may continue. All of those have led and may in the future lead to pricing pressures, and result in competitors with greater resources than us and may harm our competitive position. Further, it is possible that domestic or foreign companies or governments, some with substantial experience in digital investigative and intelligence solutions, public safety sector or law enforcement software and systems industry or greater financial resources than we possess, will seek to develop and provide solutions that compete directly or indirectly with ours in the future. Any such foreign competitor, for example, could benefit from subsidies or other protective measures by its home country. 10 Table of Content Competition may increase and intensify in the future as the pace of technological change and adaptation quickens and as additional companies enter our markets. Numerous releases of competitive products have occurred in recent years and are expected to continue in the future. We may not be able to compete effectively with current competitors and potential entrants into our marketplace. We could lose market share if our current or prospective competitors: (i) develop technologies that are perceived to be substantially equivalent or superior to our technologies, (ii) introduce new competitive products or services, (iii) add new functionality to existing products and services, (iv) acquire competitive products and services, (v) reduce prices, or (vi) form strategic alliances or cooperative relationships with other companies. If other businesses were to engage in aggressive pricing policies with respect to competing products, as they have done in the past, or if the dynamics in our marketplace resulted in increasing bargaining power by the consumers of our solutions, we might need to lower the prices we charge for the solutions we offer, as we were forced in the past. This could result in lower revenue or reduced profit margins, either of which may materially adversely affect our business and operating results. Finally, as we expand our offerings, we expect to face additional competition. For example, in the market for digital investigative and intelligence solutions, there are numerous brands and solutions that compete for sales, with purchasing decisions often based upon brand recognition and loyalty, product packaging, quality and innovation, licensing models, price and convenience. Hence, changes in our image, packaging and licensing models could have a negative impact on our customers’ preference for us, which could adversely affect our ability to attract or retain customers. If we are unable to compete successfully, our business, financial condition and results of operations could be adversely affected. If our solutions are misused by customers, such customers may achieve sub-optimal results, which could lead to the perception that our solutions are low-quality. If our customers do not use our solutions correctly or as intended, inadequate performance or outcomes may result. Our solutions are sometimes used by customers with smaller or less sophisticated professional practitioners and IT departments, potentially resulting in such suite of solutions performing at a lower-than-anticipated level by the customer. Our customers rely on our solutions to assist them in addressing important goals and challenges, and the incorrect or improper use or configuration of our solutions may result in customer dissatisfaction, contract terminations or non-renewals, reduced customer payments, negative publicity, or legal claims against us. Furthermore, although we invest in ongoing, proactive outreach by our customer experience staff and offer extensive training options to customers, if customer personnel do not opt to enroll in training, stay current on the use of our solutions, are not receptive to our outreach or are not well trained in the use of our solutions, customers may not realize the full value of our solutions, open more support tickets, turn to our technical support more often, demand the attention of our customer satisfaction teams, or may defer the deployment of our solutions and solutions, may deploy them in a more limited manner than originally anticipated, or may not deploy them at all. If there is substantial turnover of customer personnel responsible for procurement and/or use of our solutions, our solutions may go unused or be adopted less broadly, and our ability to secure license renewal or make additional sales may be substantially limited, which could negatively impact our business, results of operations, and growth prospects. 11 Table of Content If we fail to manage future growth effectively, our business could be harmed. For the last several years, we have experienced notable business growth. For example, our revenue has grown from $271 million in 2022 to $476 million in 2025, and our headcount has increased from 1,005 employees as of December 31, 2022 to 1,285 employees as of December 31, 2025. We operate in a growing market and have experienced, and may continue to experience, significant expansion of our operations. This growth has placed, and may continue to place, a strain on our employees, management systems, operational, financial, and other resources. As we have grown, we have increasingly managed larger and more complex deployments of our solutions with a broader base of public and private sector customers. As we continue to grow, we face challenges of recruiting, integrating, developing, retaining, and motivating a growing employee base in various countries around the world. In the event of continued growth of our operations, our operational resources, including our information technology systems, our employee base, or our internal controls and procedures may not be adequate to support our operations. Managing our growth may require significant expenditures and allocation of valuable management resources, improving our operational, financial, and management processes and systems, and effectively expanding, training, and managing our employee base. If we fail to achieve the necessary level of efficiency in our organization as it grows, our business, financial condition, and results of operations would be harmed. As our organization continues to grow, we may find it increasingly difficult to maintain the benefits of our traditional company culture, including our ability to quickly respond to customers, and avoid a formal corporate structure. This could negatively affect our business performance or ability to hire or retain personnel in the near or long-term. In addition, our ability to forecast our future results of operations is subject to a number of uncertainties, including our ability to effectively plan for and model future growth. We may encounter risks and uncertainties frequently experienced by growing companies with global operations in rapidly changing industries. If we fail to achieve the necessary level of efficiency in our organization as it grows, or if we are not able to accurately forecast future growth and plan for it, our business, financial condition, and results of operations would be harmed. 12 Table of Content Our business depends on our customers renewing their subscriptions and purchasing additional subscriptions or services from us. Any material decline in our dollar-based net retention rate would harm our future results of operations. We offer our software solutions primarily through annual and multi-year subscription agreements. To continue to grow our business and improve our operating results, it is important that our customers renew their subscriptions when existing contract terms expire and that we expand our commercial relationships with our existing customers either by increasing their use of existing solutions or by subscribing to new software solutions from us. Our customers have no obligation to renew their subscriptions, and may decide not to renew their subscriptions with a similar contract period, at the same prices and terms or with the same or a greater number of units or users, as applicable. We have experienced growth primarily by selling additional subscriptions to our solutions to our existing customer base, but there can be no assurances that we will achieve similar growth rates in the future. In the past, some of our customers have elected not to renew their agreements with us or have reduced the scope of their agreements with us when they renewed their agreements, and it is difficult to accurately predict long-term customer retention and expansion rates. Our customer retention and expansion may decline or fluctuate as a result of a number of factors, including our customers’ satisfaction with our products, our product support, our prices and pricing plans, global economic conditions, the inflation and interest rate environment and increased costs, the prices of competing software products, reductions in our customers’ spending levels, user adoption of our solutions, utilization rates by our customers, new product releases and changes to the packaging of our product offerings. If our customers do not purchase additional subscriptions or renew their subscriptions, renew on less favorable terms or fail to add more users or units, our revenue may decline or grow less quickly than anticipated, which would harm our future results of operations. Furthermore, if our contractual subscription terms were to shorten, it could lead to increased volatility of, and diminished visibility into, future recurring revenue. If our sales of new or recurring subscriptions and related professional service contracts decline from current levels, our revenue and revenue growth may decline, and our business will suffer. We conduct a relatively low volume of our business via e-commerce, which may result in the purchase process being more difficult for customers compared with other businesses. We do not sell our solutions to new customers using e-commerce methods. While customers can initiate contact with us using our website, the ultimate purchase in most cases is not made through our website and is made only after an interactive discussion with the customer. For example, our sales process involves “know your customer” vetting and screening procedures prior to approving the prospect as a customer. As a result, the purchase process can be lengthier than traditional e-commerce transactions, and it is possible that the length of the process may discourage some customers from completing the transaction with us rather than with a competitor who offers more seamless online sales. 13 Table of Content Issues in the use of AI (including machine learning) in our solutions may result in reputational harm, liability or impact our financial results. We have integrated a range of AI-powered features and capabilities across our portfolio of solutions. For example, our Cellebrite Pathfinder solution, our principal investigative analytics tool, uses AI to allow customers to create unique search categories for reviewing text, video and image evidence. The evolution of AI, including the recent introduction of Generative AI by third-party providers as well as competing AI engines and agentic AI, present opportunities for further efficiencies in digital investigations. Failing to adopt such capabilities effectively within our offerings may harm our ability to effectively compete in the market. At the same time AI presents risks and challenges that could affect its further development, adoption, and use, and therefore our business, products, services and revenues. AI algorithms may be flawed and may present risks due to a lack of back-testing. Datasets in AI training, development and/or operations may be insufficient, of poor quality, or embed unwanted forms of bias. Outputs of AI systems may include hallucinations, bias or other forms of discrimination. Inappropriate or controversial data practices by, or practices reflecting inherent biases of, data scientists, engineers, and end-users of our systems could impair the acceptance of AI enhanced solutions. If the recommendations, forecasts, or analyses that AI-powered applications assist in producing are deficient or inaccurate, we could be subjected to competitive harm, potential legal liability, and brand or reputational harm. Although we seek to maintain human oversight and control over AI-assisted processes, and have governance oversight to prevent material decisions from being made autonomously by AI systems without human involvement, agentic AI models could take unanticipated actions, generate unauthorized code paths or initiate transactions that breach client policies, regulatory requirements or our internal controls, or produce outputs or take action that is incorrect, or reflect biases included in the training data that results in infringements on property rights of others or is otherwise harmful. Some AI scenarios present ethical issues, for example, due to unintentional biases that may stem from the predictive nature of AI algorithms and we may enable or offer solutions that draw controversy due to their perceived and actual impact on society. We could suffer reputational or competitive damage as a result of any inconsistencies in the application of the technology or ethical concerns all of which may generate negative publicity. We could also face regulatory or legal scrutiny, such as a result of potential procedural due process claims stemming from the use of the technology. We may not be successful in our AI initiatives, which could adversely affect our business, reputation, or financial results. The regulatory framework for AI is rapidly evolving as many federal, state, and foreign government bodies and agencies have introduced or are currently considering additional laws and regulations. For example, in Europe, the EU Artificial Intelligence Act (the “EU AI Act”) and establishes a comprehensive, risk-based governance framework for AI systems in the EU market. The EU AI Act includes requirements around transparency, conformity assessments and monitoring, risk assessments, human oversight, security, accuracy and general purpose AI. Penalties under the EU AI Act vary depending on the type of violation. Violations of the prohibited AI restrictions are subject to administrative fines to the higher of 7% of worldwide annual turnover or €35,000,000, and violations of most of the EU AI Act’s other provisions are the higher of 3% annual worldwide turnover or €15,000,000. Further, the supply of incorrect, incomplete, or misleading information to the competent authorities in certain contexts can result in fines of the higher of €7,500,000 or 1% of a company’s total worldwide annual turnover. Some requirements may be subject to change as the European Commission recently announced proposed adjustments to the EU AI Act in November 2025. Further, as another example of the rapidly evolving AI regulatory framework, the proposed EU Cloud and AI Development Act reflects the European Union’s additional efforts to regulate AI infrastructure, cloud capacity, and the development and deployment of AI technologies, and, if adopted, may impose additional compliance obligations on our operations in the EU market. 14 Table of Content For example, In the United States, the California Privacy Protection Agency finalized regulations under the California Consumer Privacy Act regarding the use of automated decision-making. California and other states have passed additional laws and are considering laws governing the use and development of AI technologies. Such additional regulations may impact our ability to develop, use and commercialize AI technologies in the future. Additionally, existing laws and regulations may be interpreted in ways that may affect our use of AI. As a result, implementation standards and enforcement practices are likely to remain uncertain for the foreseeable future, and we cannot yet determine the impact future laws, regulations, standards, or market perception of their requirements may have on our business and may not always be able to anticipate how to respond to these laws or regulations. Uncertainty around new and evolving AI regulations and uses may require significant, additional investment to develop models and responsible-use frameworks. We have experienced, and may in the future experience, challenges accessing AI models, datasets or hardware. Developing, testing and deploying AI systems may also increase the cost of our offerings, including due to the nature of the computing costs involved in such systems. These costs could adversely impact our margins as we continue to make significant investments in AI development, add AI capabilities to our offerings and scale our AI offerings without assurance that our customers and users will adopt them. Additionally, concerns, skepticism, and potential misconceptions among customers, regulators and judicial systems regarding the use of AI and compliance with evolving AI regulations, particularly in relation to the responsible and ethical use of AI in the law enforcement sector, may impact adoption rates, create legal and reputational risks, and necessitate the implementation of additional compliance measures. Further, as with any new offerings based on new technologies, consumer reception and monetization pathways are uncertain, our strategies may not be successful and our business and financial results could be adversely impacted. New AI offerings and technologies could modify workforce needs, result in negative publicity about AI and decrease demand for our existing products, services and solutions, all of which could adversely impact our business. Compliance with these laws and regulations may be onerous and expensive, and may be inconsistent from jurisdiction to jurisdiction, further increasing the cost of compliance and the risk of liability. Any such increase in costs or increased risk of liability as a result of changes in these laws and regulations or in their interpretation could individually or in the aggregate make our products and services that use AI technologies less attractive to our customers, cause us to change or limit our business practices or affect our financial condition and operating results. We may require additional capital to support the growth of our business, and this capital might not be available on acceptable terms, if at all. As of December 31, 2025, we had cash and cash equivalents of $124.5 million, short-term deposits of $161.0 million and short-term and long-term marketable securities of $249.5 million. We expect to meet our ongoing liquidity needs for at least the current year. However, we may require substantial additional financing in order to execute our inorganic growth strategy. Such financing may not be available on commercially reasonable terms or at all. If we are unable to obtain such financing, or secure sufficient customer agreements, on commercially reasonable terms, or at all, we will not be able to execute our growth strategy. 15 Table of Content To the extent that we raise additional capital through the sale of equity or convertible debt securities, the ownership interest of our current security holders will be diluted, and the terms of those securities may include liquidation or other preferences that adversely affect the rights of our current holders of Ordinary Shares. Debt financing and preferred equity financing, if available, may involve agreements that include covenants limiting or restricting our ability to take specific actions, such as incurring additional debt, making acquisitions or capital expenditures or declaring dividends. Debt financing could also have significant negative consequences for our business, results of operations and financial condition, including, among others, increasing our vulnerability to adverse economic and industry conditions, limiting our ability to obtain additional financing, requiring the dedication of a substantial portion of our cash flow from operations to service our indebtedness, thereby reducing the amount of our cash flow available for other purposes, limiting our flexibility in planning for, or reacting to, changes in our business, and placing us at a possible competitive disadvantage compared with less leveraged competitors or competitors that may have better access to capital resources. If we raise additional funds through collaborations, strategic alliances or marketing, distribution or licensing arrangements with third parties, we may have to relinquish valuable rights to our technologies, future revenue streams, research programs or solutions, or grant licenses on terms that may not be favorable to us. If we are unable to raise additional funds through equity or debt financings or other arrangements when needed, we may be required to delay, limit, reduce or terminate our commercialization, research and development efforts or grant rights to third parties to market and/or develop solutions that we would otherwise prefer to market and develop ourselves. Higher costs or unavailability of materials used to create our hardware product components could adversely affect our financial results. Our supply chain for sourcing various components used in the assembly of our hardware product components is dynamic and complex. We depend on certain suppliers for the delivery of such components and have strived to limit our dependence on any one particular supplier. In particular, we use specialized adapters, which connect our software to the mobile devices and computers being examined and offers additional layers of security. If we become unable to obtain the components necessary for our hardware products, we may struggle to fulfill contracts and acquire new customers. We generally keep substantial inventory on hand for long lead-time components to mitigate this risk, which we believe would give us enough time to resolve shortage due to an issue with a particular supplier, but it might not be enough time to resolve a shortage that stems from general market scarcity. Any interruption of supply for any material components of our products could significantly delay the shipment of our products and have a material adverse effect on our revenue, profitability and financial condition. International or domestic geopolitical or other events, including the ongoing conflict between Israel and Hamas and tensions in the Middle East as well as the current, or any potential, escalation between Israel and Iran and its proxies, and/or the imposition of new or increased tariffs and/or quotas by the U.S. federal government on any of these raw materials or components, could adversely impact the supply and cost of these raw materials or components, and could adversely impact the profitability of our operations. Additionally, if we experience an unpredicted increase in customer demand, we might not be able to acquire enough materials to meet that demand in a timely manner and/or incur higher costs than expected due to increased demand. 16 Table of Content Fluctuations in foreign currency exchange rates could materially affect our financial results. Our financial statements are presented in U.S. dollars. Because some of our revenue, operating expenses, assets and liabilities are denominated in foreign currencies, we are subject to foreign exchange risks that could adversely affect our operations and reported results. To the extent that we incur expenses in one currency but earn revenue in another, any change in the values of those foreign currencies relative to the U.S. dollar could cause our profits to decrease (as was the case in 2022 and in 2025) depending on the magnitude of the changes in foreign currencies, or our products to be less competitive against those of our competitors. To the extent that our foreign currency holdings and other assets denominated in a foreign currency are greater or less than our liabilities denominated in a foreign currency, we have foreign exchange exposure. More specifically, for current and potential international customers whose contracts are denominated in U.S. dollars, the relative change in local currency values creates relative fluctuations in our product pricing. These changes in international end customer costs may result in lost or delayed orders and reduce the competitiveness of our solutions in certain foreign markets. Additionally, intercompany sales to our non-U.S. dollar functional currency international subsidiaries are transacted in U.S. dollars which could increase our foreign exchange rate risk caused by foreign currency transaction gains and losses. For non-U.S. dollar denominated sales, weakening of foreign currencies relative to the U.S. dollar generally leads us to raise international pricing, potentially reducing demand for our solutions. Should we decide not to raise local prices to fully offset the U.S. dollar’s strengthening, the U.S. dollar value of our foreign currency denominated sales and earnings would be adversely affected. Fluctuations in foreign currency could result in a change in the U.S. dollar value of our foreign denominated assets and liabilities including accounts receivable. Therefore, the U.S. dollar equivalent collected on a given sale could be less than the amount invoiced causing the sale to be less profitable than contemplated. Approximately 32% of our expenses, primarily payroll and rent, are paid in Israeli new shekels (NIS). The U.S. dollar compared with the NIS experienced meaningful volatility over the last several years, which, if it continues to present the same behavior, could have an adverse impact on our expenses and profitability. Although we take steps to hedge our foreign currency exposures related to our NIS expenses, such measures may not adequately protect us from material adverse effects arising from the impact of local conflicts, including the ongoing Israel-Hamas conflict and tensions in the Middle East, global inflation or from fluctuations in the relative values of the U.S. dollar and other foreign currencies in which we transact business, and may result in a financial loss. The sales cycle for some of our solutions can be lengthy. Most of our sales transactions for digital forensics software involve a relatively short sales cycle; however, larger transactions, especially those involving a large-scale upgrade to our Inseyets solution or those involving broader adoption of multiple flagship offerings within our digital investigation platform may result in a longer sales cycle and may require, for example, discussions about budget and funding and about which potential solution is most suitable to the customer. The larger the sale, the longer these consultations tend to last. If our sales efforts to a potential customer do not result in sufficient revenue to justify our time and investments, our business, financial condition and results of operations could be adversely affected. We continue to expand our sales of multiple offerings to customers, and the impact of these longer sales cycles could become more significant over time. Because of the long approval process that typically accompanies strategic initiatives or capital expenditures by our customers, our sales process may be prolonged, revenue delayed, with little or no control over any delays encountered by us. 17 Table of Content Because most of our revenue is derived from subscriptions, which is recognized over the life of the subscription, near-term declines in new or renewed agreements may not be reflected immediately in our operating results and may be difficult to discern. Most of our revenue in each quarter is derived from subscription agreements entered into with our customers during previous quarters. Consequently, a decline in new or renewed agreements in any one quarter may not be fully reflected in our revenue for that quarter. Such declines, however, would negatively affect our revenue in future periods and the effect of significant downturns in sales of and market demand for our offerings, and potential changes in our rate of renewals or renewal terms, may not be fully reflected in our results of operations until future periods. Annual Recurring Revenue, or ARR, is a key performance metric we use that is based on contractual terms in existence as of the end of a reporting period and is subject to change resulting from a number of factors including, but not limited to, addition of new customers, changes in user counts, terminations or non-renewals, renewal terms as well as upsells and cross-sells. For all of these reasons, the amount of subscription revenue we actually recognize will differ from ARR at the end of a period in which it was recorded. In addition, we may be unable to adjust our cost structure rapidly, or at all, to take account of reduced revenue if demand for new or renewed agreements deteriorates. Our subscription model also makes it difficult for us to rapidly increase our total revenue through additional sales in any period, as revenue from new subscriptions, which has historically comprised the majority of our revenue, is recognized over the applicable term of the agreement. The security of our operations and the integrity of our software solutions are critical to our operations and to maintaining the trust and confidence of our customers. There can be no assurance that the measures we have taken to protect our operations and solutions will prevent all malicious activities, including deliberate insertion of exploitative code, malware or cyberattacks, or inadvertent disclosures (including of personal information, sensitive investigative data or confidential business information) or unauthorized access, from impacting our system and information. There can be no assurance that our software updates can keep up with evolving security and encryption strategies in the industry, and, as a result, our software may be vulnerable to malicious attacks. We may also experience breaches of our security due to human error, malfeasance, system errors or vulnerabilities, or other irregularities. As the techniques used to obtain unauthorized access change frequently, we may be unable to anticipate these techniques or to implement adequate preventative measures. Although to date, malicious activities directed at us have not had a material impact on our business nor, to our knowledge, have they impacted the integrity of the data that our solutions extract from devices, analyze or store, future malicious activities could compromise our solutions and cause us to incur liabilities that may have a material adverse impact on our reputation and business. While we maintain insurance coverage that we believe is adequate for our business, such coverage may not cover all potential costs and expenses associated with incidents that may occur in the future. 18 Table of Content We may be materially adversely affected by negative publicity related to our business and use of our products. As our business has grown and as interest in Cellebrite and digital investigative and intelligence technology overall has increased, we have attracted, and may continue to attract, coverage from news and other outlets. Such coverage may be influenced by or lead to negative political and public sentiment. For example, perceived data security, ethical and other concerns have resulted in adverse press coverage of our digital forensics software. Moreover, adverse press coverage and other negative publicity may also result in investigations by regulators, legislators and law enforcement officials or ultimately in legal claims. Due to the sensitive nature of our work and our confidentiality obligations and despite our ongoing efforts to provide increased transparency, when possible, into our business, operations, and product capabilities, we may be unable to or limited in our ability to effectively respond to such harmful coverage, which could have a negative impact on our business. Responding to such coverage, claims, investigations and lawsuits, regardless of the ultimate outcome of the proceeding, can also divert the time and effort of senior management from the management of our businesses. Addressing any adverse publicity, governmental scrutiny or enforcement or other legal proceedings is time consuming and expensive and, regardless of the factual basis for the assertions being made, can have a negative impact on our reputation, the morale and performance of our employees and our relationships with regulators. It may also have an adverse impact on our ability to take timely advantage of various business and market opportunities. Additionally, political and social activist criticism of our relationships with customers could potentially engender dissatisfaction among potential and existing customers, investors, and employees with how we address political and social concerns in our business activities, such as ceasing to do business in certain jurisdictions. See “—Some of our solutions may be used by customers in a way that is, or that is perceived to be, incompatible with human rights. Any such perception could adversely affect our reputation, revenue and results of operations”. Conversely, being perceived as yielding to activism targeted at certain customers could damage our relationships with other customers, including governments and government agencies with which we do business, whose views may or may not be aligned with those of political and social activists. Actions we take in response to the activities of our customers, up to and including terminating our contracts or refusing a particular product use case could harm our brand and reputation. The direct and indirect effects of such factors, negative publicity, and the demands of responding to and addressing them, may have a material adverse effect on our businesses, financial condition and results of operations. We have entered into agreements with the U.S. government with respect to entities that we have acquired and would face adverse consequences if we do not comply with these agreements. In July 2024, we acquired Cyber Technology Services(“CyTech”), a professional services provider with extensive expertise in cybersecurity, digital forensics and incident response services. CyTech’s operations require it to issue facility security clearances under the National Industrial Security Program (“NISP”). The NISP requires that a corporation maintaining a facility security clearance be effectively insulated from foreign ownership, control or influence (“FOCI”). Because we are organized in Israel, we entered into an agreement with the U.S. Department of Defense with respect to FOCI mitigation arrangements that relate to this portion of our business. Failure to adhere to these FOCI mitigation requirements could result in the discontinuation of CyTech’s facility security clearance, adversely impacting its ability to perform on classified contracts, and would further mean that we would not be able to enter into future contracts with the U.S. government requiring facility security clearance. Further, if we fail to adhere to the FOCI mitigations or violate our FOCI mitigation agreement, we may be suspended or barred from participating in government contracts, whether classified or unclassified. 19 Table of Content In December 2025, we acquired Corellium, a leader in virtualization software for devices that rely on power-efficient Arm processors. The Committee on Foreign Investment in the United States (CFIUS) has permitted the acquisition to close on the basis of a national security agreement negotiated with relevant government agencies and executed by Cellebrite and Corellium pending formal clearance by CFIUS and execution of that agreement by such agencies. Accordingly, the interim national security agreement, among other things, requires us to maintain Corellium as a separate entity, forgo access to certain Corellium technology or limit access to designated personnel, maintain supply of certain products to the U.S. government, and operate aspects of its business which interface with the U.S. government in a manner that complies with other restrictions and requirements. If we violate the interim national security agreement, we could become subject to civil penalties in addition to claims by the U.S. government, including injunctive relief. Furthermore, there can be no assurance that such formal clearance will be granted to us. If we are unable to obtain formal clearance from CFIUS, we may be required to divest some or all of our interests in Corellium, unwind the acquisition, or take other actions that could materially and adversely affect our ownership or operation of Corellium. In addition, we could face challenges in effecting other acquisitions that are subject to review by CFIUS. The impacts set forth above could have a negative effect on our long-term plans, business operations, financial condition, and results of operations. 20 Table of Content Risks Related to the Businesses of Cellebrite’s Customers Our sales to government customers expose us to business volatility and risks, including government budgeting cycles and appropriations, early termination, audits, investigations, sanctions and penalties. We generate the significant majority of our revenue from contracts with federal, state, provincial and local governments (which we refer to as our “Public Sector Customers”), and many of these Public Sector Customers may terminate most of these contracts at any time, without cause. There is pressure on some Public Sector Customers, both domestically and internationally, to reduce spending. Further, U.S. federal government contracts are subject to the approval of appropriations made by the U.S. Congress to fund the expenditures under these contracts. In particular, budget uncertainty, the risk of future budget cuts, the potential for U.S. Government shutdowns, the use of continuing resolutions, and the U.S federal debt ceiling could adversely affect our industry and the funding for our solutions. If appropriations were delayed or a government shutdown were to occur and were to continue for an extended period of time, we could be at risk of disruptions to our business. Similarly, our contracts with U.S. state and local governments as well as other foreign governments and their agencies are generally subject to government funding authorizations. Additionally, government contracts are generally subject to audits and investigations, which could result in various civil and criminal penalties and administrative sanctions, including termination of contracts, refund of a portion of fees received, forfeiture of profits, suspension of payments, fines and suspensions or debarment from future government business. A decline in government budgets, changes in spending or budgetary priorities, or delays in contract awards may significantly and adversely affect our future revenue and limit our growth prospects. We generated more than 90% of our revenue in 2023, 2024 and 2025 from contracts with Public Sector Customers and our results of operations would be adversely affected by government spending caps or changes in government budgetary priorities, as well as by delays in the government budget process, program starts, or the award of contracts or orders under existing contract vehicles. Further, these Public Sector Customers face increased pressure to reduce spending and may terminate most of these contracts at any time, without cause. See “— Risks Related to Our Business and Industry —.” We are dependent on acceptance of our solutions by our Public Sector Customers, both domestic and international. If law enforcement and other government agencies do not continue to purchase, accept and use our solutions, our revenue will be adversely affected. Future spending and program authorizations may not increase or may decrease or shift to programs in areas in which we do not provide services or are less likely to be awarded contracts. Budgetary constraints for political or economic reasons, particularly in light of the Russia-Ukraine conflict, the Israel-Hamas conflict and tensions in the Middle East due to the widening regional conflict may also cause our governmental customers to divert budget and may result in them forgoing use of our solutions. We face these risks in every country in which we operate. 21 Table of Content Revenue from the U.S. federal government customers accounted for approximately 16% of our total revenue in 2025. Those contracts are conditioned upon the continuing availability of U.S. Congressional appropriations. The U.S. Congress usually appropriates funds on a fiscal year basis even though contract performance may extend over many years. Consequently, contracts are often partially funded initially and additional funds are committed only as the U.S Congress makes further appropriations over time. If we incur costs in excess of funds obligated on a contract or in advance of a contract award, we may be at risk of not being reimbursed for those costs unless and until additional funds are obligated under the contract or the contract is awarded and funded. Additionally, when the U.S. Congress does not complete a budget before the end of the fiscal year, government operations typically are funded through one or more continuing resolutions that authorize agencies of the U.S. federal government to continue to operate consistent with funding levels from the prior year’s appropriated amounts, but do not authorize new spending initiatives. When the U.S. federal government operates under a continuing resolution, contract awards may be delayed, canceled, or funded at lower levels, which could adversely impact our business, financial condition, and results of operations. If appropriations or continuing resolutions for the U.S. federal government departments and agencies with which we work or have prospective business are not made by September 30 (the last day of the federal fiscal year) of any given year, the lapse in appropriations may also have negative impacts on our ability to continue work and to recognize revenue from those customers, for so long as the lapse continues. In particular, when the U.S. Government operates under a continuing resolution, new contract and program starts are restricted and funding for our solutions may be unavailable, reduced or delayed. Shifting funding priorities or federal budget compromises, could also result in reductions in overall defense spending on an absolute or inflation-adjusted basis, which could adversely impact our business. The U.S. federal government may also shift spending away from one or more of the federal agencies from which we derive revenue for budgetary or political reasons. Currently, considerable uncertainty exists regarding how future budget and program decisions will develop, including the spending priorities of the Trump Administration and Congress, and the magnitude and timing of potential funding to support future spending on our products specifically and within our industry generally. These changes may also impact the level of funding for certain federal agencies or the level of funding to state and local law enforcement agencies. Pressures on and uncertainty surrounding the U.S. federal government’s budget, and potential changes in budgetary priorities and spending levels, could adversely affect the funding for and delay or eliminate the ability for additional purchases of our solutions, including at the state level which depends on the federal government in part for its funding. These factors could adversely affect our future revenue and limit our growth prospects. 22 Table of Content Evolving government procurement policies and increased emphasis on cost over performance could adversely affect our business. A significant majority of our customers are public sector customers. The procurement processes for government agencies can be more challenging than contracting in the private sector, and they can impose additional costs and complicate sales efforts. Further, changes in the political landscape or required procurement procedures that affect our current and prospective customers could be introduced prior to the completion of our sales cycle, making it more difficult or costly to finalize a contract with a new customer or expand or renew an existing customer relationship. For example, customers may require a competitive bidding process with extended response deadlines, review or appeal periods; or customers may need to secure funding, which could result in purchasing delays or cancellations; or customer attention may be diverted to other government matters, postponing the consideration of the purchase of our solutions. Such delays could harm our ability to provide our solutions efficiently and to grow or maintain our customer base. In addition, the majority of our government contracts include the right for government agencies to delay, curtail, renegotiate or terminate contracts and subcontracts at their convenience any time prior to their completion. Any decision by a government customer to exercise any of these rights in our contracts may result in a decline in our profits and revenue. Changes in civil forfeiture laws may affect our customers’ ability to purchase our solutions. Many of our law enforcement customers in the United States use funds seized through civil forfeiture proceedings to fund the purchase of our solutions. State civil forfeiture statutes permit state governments to seize property with limited judicial oversight, often based on a preponderance of the evidence that the property was connected to criminal activity even if the owner of the property is not subject to criminal charges. An adverse U.S. Supreme Court decision or changes in state legislation could impact our customers’ ability to seize funds or use seized funds to fund purchases of our solutions. Changes in civil forfeiture statutes or regulations are outside of our control and could limit the amount of funds available to our customers, which could adversely affect the sale of our solutions. Our revenue from private sector customers, and our operations in general, could be adversely affected by any weakening of economic conditions. Our private sector customers may be more susceptible to weakening economic conditions than our Public Sector Customers. Certain economies have experienced periods of downturn as a result of a multitude of factors, including, but not limited to, turmoil in the credit and financial markets, concerns regarding the stability and viability of major financial institutions, declines in gross domestic product, increases in unemployment, volatility in commodity prices and in the worldwide stock markets, higher interest rates, potential governmental shutdowns, natural catastrophes, warfare, the geopolitical turmoil caused by the ongoing conflicts between Russia and Ukraine, Israel and Hamas and the overall volatility and violence in the Middle East, inflation, excessive government debt and disruptions to global trade or tariffs. The severity and length of time that a downturn in economic and financial market conditions may persist, as well as the timing, strength and sustainability of any recovery, are unknown and are beyond our control. Any instability in the global economy affects countries in different ways, at different times and with varying severity, which makes the impact to our business complex and unpredictable. During such downturns, many customers may delay or reduce technology purchases. Contract negotiations may become more protracted or conditions could result in reductions in the sales of our software, hardware and solutions, longer sales cycles, pressure on our margins, difficulties in collection of accounts receivable or delayed payments, increased default risks associated with our accounts receivables, slower adoption of new technologies and increased price competition. While none of these delays have been significant, they may become significant in the future or transition from delays to outright cancellation. 23 Table of Content In addition, deterioration of the global credit markets could adversely impact our ability to complete licensing transactions and services transactions. Any of these events, as well as a general weakening of, or declining corporate confidence in, the global economy, or a curtailment in corporate spending could delay or decrease our revenue and therefore have a material adverse effect on our business, operating results and financial condition. 24 Table of Content Risks Related to Cellebrite’s Intellectual Property Failure to adequately obtain, maintain, protect and enforce our intellectual property and other proprietary rights could adversely affect our business. Our success and ongoing ability to compete depends in part on maintaining, protecting, enforcing and defending our intellectual property and other proprietary rights. Our suite of digital investigative solutions is based on proprietary software and related intellectual property rights. We rely upon a combination of copyright, trademark, patent and trade secret laws, as well as certain contractual provisions, to establish, maintain, protect and enforce our intellectual property and other proprietary rights, including those relating to our technology and solutions. In addition, we license technology from third parties that is integrated into some of our solutions, including third-party software that facilitates access to certain devices. Despite our efforts, third parties may attempt to disclose, obtain, copy, or use our intellectual property or other proprietary information or technology without our authorization, and our efforts to protect our intellectual property and other proprietary rights may not prevent such unauthorized disclosure or use, misappropriation, infringement, reverse engineering or other violation of our intellectual property or other proprietary rights. The laws of other countries in which our solutions are available may not be as effective or protective of intellectual property and other proprietary rights as those in Israel or the United States, and mechanisms for enforcement of intellectual property and other proprietary rights may be inadequate. Additionally, the intellectual property ownership and license rights of new technologies such as those generated using AI have not been fully addressed by U.S. courts interpreting current and new laws or regulations, and the use or adoption of such technologies in our products and services may expose us to potential intellectual property claims; breach of a data license, software license, or website terms of service allegations; claimed violations of privacy rights; and other tort claims. If such laws or regulations require increased transparency, it may impair protection of our trade secrets or other intellectual property. In addition, our involvement in standard setting activity or the need to obtain licenses from others may require us to license our intellectual property. Accordingly, despite our efforts, we may be unable to prevent third parties from using our intellectual property or other proprietary information or technology. The violation of our licensing agreements by transferring or allowing the use of our intellectual property, proprietary information or technology without a license may pose additional risks. We may become the subject of intellectual property infringement or misappropriation claims, which could be time-consuming and expensive to settle or litigate and could divert our management’s attention and other resources. These claims could also subject us to significant liability for damages if we are found to have infringed patents, copyrights, trademarks, or other intellectual property rights, or breached trademark co-existence agreements or other intellectual property licenses and could require us to cease using or to rebrand all or portions of our solutions. Any of our intellectual property rights may be challenged, narrowed, invalidated, held unenforceable, or circumvented in litigation or other proceedings, including, where applicable, opposition, re-examination, inter partes review, post-grant review, interference, nullification and derivation proceedings, and equivalent proceedings in foreign jurisdictions, and such intellectual property or other proprietary rights may be lost or no longer provide us meaningful competitive advantages. Such proceedings may result in substantial cost and require significant time from our management, even if the eventual outcome is favorable to us. 25 Table of Content In September 2024, we announced the patent for our Remote Mobile Collection solution. We seek patent protection and may in the future determine that we require additional patents in order to protect our software and processes, and we may be unable to obtain patent protection for the technology covered in our patent applications or such patent protection may not be obtained quickly enough to meet our business needs. Furthermore, the patent prosecution process is expensive, time-consuming, and complex, and we may not be able to prepare, file, prosecute, maintain, and enforce all necessary or desirable patent applications at a reasonable cost or in a timely manner. The scope of patent protection also can be reinterpreted after issuance and issued patents may be invalidated. Even if our patent applications do issue as patents, they may not issue in a form that is sufficiently broad to protect our technology, prevent competitors or other third parties from competing with us or otherwise provide us with any competitive advantage. Third parties may legitimately and independently develop products, services, and technology similar to or duplicative of our products, services and technology. In addition to protection under intellectual property laws, we rely on confidentiality or license agreements that we generally enter into with our corporate partners, employees, consultants, advisors, vendors, and customers, and we generally limit access to and distribution of our intellectual property and proprietary information. However, we cannot be certain that we have entered into such agreements with all parties who may have or have had access to our confidential information or that the agreements we have entered into will not be breached or challenged, or that such breaches will be detected. Furthermore, confidentiality and non-disclosure provisions can be difficult to enforce, and even if successfully enforced, may not be entirely effective. We cannot guarantee that any of the measures we have taken will prevent infringement, misappropriation, or other violation of our technology or other intellectual property or proprietary rights. Moreover, we spend significant resources to monitor and protect our intellectual property and other proprietary rights from potential infringement, and in the future we may conclude that in at least some instances the benefits of protecting our intellectual property or other proprietary rights may be outweighed by the expense or distraction to our management. We may initiate claims or litigation against third parties for infringement, misappropriation, or other violation of our intellectual property or other proprietary rights or to establish the validity of our intellectual property or other proprietary rights. Any such litigation, regardless of the outcome, could be time-consuming, result in significant expense to us and divert the efforts of our technical and management personnel. Furthermore, attempts to enforce our intellectual property rights against third parties could also provoke these third parties to assert their own intellectual property or other rights against us, or result in a holding that invalidates or narrows the scope of our rights, in whole or in part. We may be subject to information technology system breaches, failures, or disruptions that could harm our operations, financial condition or reputation. There are numerous and evolving risks to cybersecurity and privacy, including criminal hackers, hacktivists, state-sponsored intrusions, industrial espionage, employee malfeasance and human or technological error. Our technology systems may be damaged, disrupted, or compromised by malicious events, such as cyberattacks (including computer viruses, ransomware, and other malicious and destructive code, phishing attacks, and denial of service attacks), physical or electronic security breaches, natural disasters, fire, power loss, telecommunications failures, personnel misconduct, and human error. Cybersecurity threats are constantly evolving, have become increasingly complex and sophisticated, and employ a wide variety of methods and techniques, which may include the use of social engineering techniques or supply-chain attacks, all of which increase the difficulty of detecting and successfully defending against such threats. Furthermore, because the techniques used to obtain unauthorized access or sabotage systems change frequently and generally are not identified until after they are launched against a target, we may be unable to anticipate these techniques or implement adequate preventative measures. 26 Table of Content In addition, security breaches at other companies and in government agencies have increased in frequency and sophistication in recent years. Other companies have also experienced cybersecurity incidents that implicate confidential and proprietary company data and/or the personal information of end users of AI applications integrated into their software offerings or used in their operations. Although we take steps designed to secure our data and information technology infrastructure and sensitive data and enhance our business continuity and disaster recovery capabilities, we can provide no assurance that our current information technology systems or any updates or upgrades thereto, including the integration of AI capabilities into our product offerings the current or future information technology systems, cloud service providers, software and hardware vendors, supply chain information technology systems that we use or may use in the future, are fully protected against third-party intrusions, viruses, hacker attacks, information or data theft or other similar cybersecurity risks. Further, a greater number of our employees are working remotely and accessing our IT systems and networks remotely since the COVID-19 pandemic, which has further increased our vulnerability to cybercrime and cyberattacks and increased the stress on our technology infrastructure and systems. We carry data protection liability insurance against cyber-attacks (including media, intellectual property & product liability, cyber liability, and commercial general liability policies), with limits we deem adequate for the reimbursement for damage to our computers, equipment and networks and the resulting disruption of our operations. However, this insurance may not be sufficient to cover all of our losses from any future breaches or failures of our IT systems, networks and services. We have experienced and expect to continue to experience actual or attempted cyber-attacks of our information technology systems or networks. Although prior known cyberattacks directed at us have not had a material impact on our business or financial results, and we are continuing to bolster our threat detection and mitigation processes and procedures, we cannot guarantee that past, future, or ongoing cyberattacks or incidents against us, if successful, will not have a material impact on our business or financial results, whether directly or indirectly. Because we have historically been targeted by cyberattacks and may continue to be an attractive target for cyberattacks, we also may have a heightened risk of unauthorized access to, and misappropriation of, our proprietary and competitively sensitive information. For instance, the risk of cyber-attacks increased in connection with the military actions associated with Russia’s invasion of Ukraine, as well as the Israel-Hamas conflict and Middle East regional conflict. In light of those and other geopolitical events, nation-state actors or their supporters may launch retaliatory cyber-attacks, or take other geopolitically motivated retaliatory actions that increase the likelihood of cyber-attacks and security breaches generally, which could disrupt our business operations, result in data compromise, or both. There can be no assurance that in the future we will be able to anticipate or prevent security breaches or incidents, or unauthorized access of our information technology systems. Any or all of these issues, or the perception that any of them have occurred, could negatively affect our ability to attract new customers, cause existing customers to terminate or not renew their agreements, hinder our ability to obtain and maintain required or desirable cybersecurity certifications, and result in reputational damage, any of which could materially adversely affect our results of operations, financial condition, and future prospects. Furthermore, there can be no assurance that any limitations of liability provisions in our license arrangements with customers or in our agreements with vendors, partners, or others would be enforceable, applicable, or adequate or would otherwise protect us from any such liabilities or damages with respect to any particular claim. 27 Table of Content Some of our software and systems contain open-source software, which may pose particular risks to our proprietary software and information technology systems. We utilize open source software in the development and application of our software solutions, and we will use open source software in the future. Such open source software is generally licensed by its authors or other third parties under open source licenses and is typically freely accessible, usable, and modifiable. Pursuant to such open source licenses, we may be subject to certain conditions, including requirements that we offer our proprietary software that incorporates the open source software for no cost, that we make available source code for modifications or derivative works we create based upon, utilizing open source software, and that we license such modifications or derivative works under the terms of the particular open source license, or other license granting third-parties certain rights of further use. If we combine our proprietary software with open source software in a certain manner, we could, under certain provisions of the open source licenses, be required to release the source code of our proprietary software. In addition to risks related to license requirements, usage of open source software can lead to greater risks than use of third-party commercial software, as open source licensors generally do not provide updates, warranties, support, indemnities, assurances of title, or controls on origin of the software, and are provided on an “as-is” basis. Likewise, some open source projects have known security and other vulnerabilities and architectural instabilities, or are otherwise subject to security attacks due to their wide availability, and are provided on an “as-is” basis. In addition, open source license terms may be ambiguous and many of the risks associated with usage of open source software cannot be eliminated, and could, if not properly addressed, negatively affect our business. If we were found to have inappropriately used open source software, we may be required to re-engineer our products, or to take other remedial action that may divert resources away from our development efforts, any of which could adversely affect our business, results of operations, financial condition, and growth prospects. We may face claims from third parties claiming ownership of, or demanding the release or license of, the open source software or derivative works that we developed from such software (which could include our proprietary source code), or otherwise seeking to enforce the terms of the applicable open source license. These claims could result in litigation and could require us to purchase a costly license, publicly release the affected portions of our source code, or cease offering the implicated software unless and until we can re-engineer it to avoid infringement. In addition, if the open source software we use is no longer maintained by the relevant open source community, then it may be more difficult to make the necessary revisions to our software, including modifications to address security vulnerabilities, which could impact our ability to mitigate cybersecurity risks or fulfill our contractual obligations to our customers. We also may be required to re-engineer solutions if the license terms for incorporated open source software change. The re-engineering process of some or all of our software could require significant additional research and development resources, and we may not be able to complete it successfully. Use of open source software may also present additional security risks because the public availability of such software may make it easier for hackers and other third parties to determine how to breach our website and systems that rely on open source software. These risks could be difficult to eliminate or manage and, if not addressed, could adversely affect our business, results of operations, and financial conditions. 28 Table of Content Other companies may claim that we infringe their intellectual property, which could materially increase costs and materially harm our ability to generate future revenue and profits. Claims of infringement (including misappropriation and/or other intellectual property violation) are common in the software industry and increasing related legal protections, including copyrights and patents, are applied to software solutions. Although most of our technology is proprietary in nature, we do include certain third party and open source software in our software solutions. In the case of third party software, we believe such software is licensed from the respective entity(ies) holding the intellectual property rights. While we believe that we have secured proper licenses for all material third-party intellectual property that is integrated into our solutions in a manner that requires a license, third parties have and may continue to assert infringement claims against us in the future, including the sometimes aggressive and opportunistic actions of non-practicing entities whose business model is to obtain patent-licensing revenue from operating companies such as us. Any such assertion, regardless of merit, may result in litigation or may require us to obtain a license for the intellectual property rights of third parties. Such licenses may not be available, or they may not be available on commercially reasonable terms. In addition, as we continue to develop software solutions and expand our portfolio using new technology and innovation, our exposure to threats of infringement may increase. Any infringement claims and related litigation could be time-consuming, expensive to settle or litigate, disruptive to our ability to generate revenue or enter into new market opportunities, could divert our management’s attention and other resources, and may result in significant liability for damages if we are found to have infringed third party rights, and/or significantly increased costs as a result of our defense against those claims or our attempt to license the intellectual property rights or rework or rebrand our solutions to avoid infringement of third party rights. Typically, our agreements with our partners and customers contain provisions which require us to indemnify them for damages sustained by them as a result of any intellectual property infringement claims involving our solutions. Any of the foregoing infringement claims and related litigation could have a significant adverse impact on our business and operating results as well as our ability to generate future revenue and profits. Risks Related to Data Privacy and Human Rights The use of certain of our solutions may be perceived as, or determined by the courts to be, in violation of privacy rights and related laws. Any such perception or determination could adversely affect our financial results and results of operations. Because of the nature of certain of our digital investigative and intelligence solutions, including those used to access, collect, review, store, share and support digital evidence, the general public could perceive that the use of our solutions may result in violations of individual privacy rights. In addition, certain courts or regulatory authorities could determine that the use of our software solutions violates privacy laws. Any such determination or perception by potential customers, the general public, government entities or judicial authorities could harm our reputation, may result in reduced usage or adoption rates of our digital investigation platform by our customers and adversely affect our reputation, revenue, financial condition and results of operations. While we dedicate resources to ensure our compliance with applicable privacy laws, we are responsible and liable for PII and other personal data which our customers entrust in our digital investigation platform and we process as part of the services we provide. We require our customers to comply with applicable privacy laws when using our products, however we may still be held responsible and even liable for the manner in which our customer uses such data, including if the customer uses the data in a way that is a violation of privacy related laws or our license agreement. 29 Table of Content Some of our solutions may be used by customers in a way that is, or that is perceived to be, incompatible with human rights. Any such perception could adversely affect our reputation, revenue and results of operations. We strive to sell our solutions to customers who will use them in a lawful and ethical manner. See “— We may not enter into relationships with potential customers if we consider their activities to be inconsistent with our organizational mission or values.” For example, all customers are required to confirm, before activation, that they will only use our product for lawful uses. However, we cannot easily, quickly or continually verify whether this undertaking is accurate. Furthermore, some of our Public Sector Customers may use our solutions in a manner that is incompatible with, or perceived to be incompatible with, generally acceptable human rights standards, without our knowledge or permission. For example, in late 2024, Amnesty International published a report alleging that certain law enforcement agencies in Serbia had misused our solutions to access the mobile phones of several journalists and activists and then implanted spyware on those devices. After a review of the allegations brought forth by the Amnesty International report, we investigated each claim in accordance with our ethics and integrity policies, and found it appropriate to stop the use of our products by the relevant customers. We have adopted policies and procedures intended to prevent sales to customers in countries that do not meet the standards we have set in our policies. As a result, we no longer sell our products to customers in China, Hong Kong, Russia, Belarus and certain other countries. Nevertheless, adverse media coverage and petitions relating to Bangladesh, Hong Kong, Russia, Serbia and Uganda have in the past negatively impacted, and may in the future negatively impact, our reputation and may also directly or indirectly cause mobile and other digital device OEMs and other software manufacturers to change their products in ways that erode or eliminate the effectiveness of our solutions. Our license agreements prohibit customers from using our solutions in a manner that violates applicable laws (including laws with respect to human rights and the rights of individuals) or in support of any illegal activity or to violate the rights of any third party, and generally and where lawful require our customers to indemnify us for losses that we suffer due to their actions. We may terminate any license, among other things, in the event of a material breach that is not cured after 30 days’ notice. In addition, we may disable the use of the software, among other things, if it is used in violation of the license. A determination regarding whether a breach of our license will result in termination or other corrective action involves judgment and depends on the facts and circumstances of each case. Nevertheless, we cannot provide any assurance that customers or others will not manage to circumvent our restrictions or that we will not be subject to claims from third parties alleging that their rights were violated as a result of our customers’ use of our products. In the future, other allegations of misuse by our customers may damage our reputation, even if we took no part in the misuse, conduct an investigation to determine the merits of any such allegations or take immediate action to sever ties with such customers. 30 Table of Content We may not enter into relationships with potential customers if we consider their activities to be inconsistent with our organizational mission or values. We generally do not knowingly enter into business with customers whose positions or actions we consider inconsistent with our mission to support law enforcement agencies acting in a lawful manner. We developed and continue to evolve an ethical risk management framework, intended to assist us in managing the risk of human rights abuses by our customers when using our products. We use the ethical framework to determine in which countries or with which customers we will pursue new business by applying a set of standards and indicators, including regulatory restrictions such as sanctions and export controls and a number of widely accepted human rights related indexes such as the Corruption Perception Index, Democracy Index and Freedom House Index. This ethical risk management framework will continue and evolve over time and applies quantitative as well as qualitative measures to aid in our decision making. Based on this ethical framework, we may decide not to engage with new customers or extend or renew licenses and services to existing customers operating in those countries that we do not consider to meet our ethical standards and corporate values. For example, we have adopted policies and procedures intended to prevent sales to customers in Bangladesh, Belarus, China, Hong Kong, Macau, Russia, Venezuela, Oman, Uganda and a number of other countries, partially due to concerns regarding human rights abuses, data privacy and security, partially due to regulatory requirements, and partially due to other business considerations, and we may in the future decide not to do business in other countries or with other existing or potential customers for similar reasons. Most of our customers require the hosting of their proprietary data within their own organization, and therefore most of our products, whether deployed on-premise or otherwise, are operated by our customers without our involvement other than with respect to troubleshooting and support from time to time. Also with respect to our SaaS-based products, while we may be involved in the operation and maintenance of the SaaS platform, we do not have visibility into our customers’ usage of our products. As a result, we rely on a range of public information sources, and largely depend on media and other reports, to learn if there is a claim made that our products are being used inconsistent with our organizational mission and values. Third party reports may be incomplete, unreliable or unavailable. In addition, a determination as to whether our products are being misused may involve subjective determinations or be the subject of differing opinions. We have in place certain safeguards that are intended to identify or prevent misuse of our products. For example, we have an Ethics and Integrity Committee, which serves as an advisory body to the board. The committee is composed of seven industry experts, which include ethics experts, legal experts, former members of the police force, former members of ministries of defense, technology experts, academic experts and community leaders. The role of the Ethics and Integrity Committee is to advise the board on matters pertaining to evolving international law, ethical considerations related to responsible business practices and requirements under law and regulations applied to the sale and use of our technologies. Our decisions not to do business within certain countries or with certain customers may alter our expectations surrounding our long-term financial benefits and results, which may harm our growth prospects, business, and results of operations. Although we endeavor to do business with customers and governments that are aligned with our mission and values, we cannot predict how the activities and values of our government and private sector customers will evolve over time, and they may evolve in a manner inconsistent with our mission. 31 Table of Content We occasionally have limited access to third-party data, and if our security measures are breached and unauthorized access to this data is obtained, our systems, data centers and our solutions may be perceived as not being secure, customers may curtail or stop using our solutions or service and we may incur significant legal and financial exposure and liabilities. We do not generally have access to or store customer data nor have access to the data processed by customers using our solutions. Nevertheless, our personnel occasionally have brief and limited access to data, including personally identifiable information (“PII”), when they receive calls for technical support or when they maintain or operate the relevant solution. One instance where we may have brief access to data is when a customer calls for technical support, they sometimes grant our service operators remote access to their device, which may result in the brief sharing of data with the service operator. In rare cases the customer may share the data with the technical support for further bug fixing research and analysis. We have internal processes for deleting such data shortly after the completion of the customer support and ensuring bug fix is sustainable and consistent, but the data is still shared for these limited periods and could potentially be, or be perceived as, more vulnerable as a result. In addition, customers may use our investigative management solution, the Guardian, to store, share and review sensitive data, including PII, when they decide to store such data in our investigative management SaaS solution. In addition, we may have access to customer data, including PII, in connection with the provision of our Advanced Services in which we serve as an outsourced forensics lab for the extraction of data from devices that are sent to us by our customers. We have implemented several internal processes and measures for deleting data shortly after completion of related services (in the case of Advanced Services), and that are designed to ensure managed, limited, brief and secure access to customers data, done strictly on a need-to-service basis. We use internationally recognized information security measures and complies with industry standards. Our Advanced Services are delivered from a strictly dedicated platform that combines authentication, authorization, networking, and observability into a single point, as well as internal processes intended to control access, usage, storage and retention of data. However, any actual or perceived unauthorized access, use, disclosure or modification to this data, could result in our solutions and services being viewed as less secure, which could lead to liability and a significant adverse effect on our reputation and financial and operating results. Risks Related to Legal Compliance and Regulatory Matters We are subject to Israeli export laws and our failure to obtain or comply with such laws or related licenses issued under these laws could negatively impact our business. The export of some of our products and our solutions is subject to Israeli export control laws and regulations which are administered primarily by the Israeli Defense Export Controls Agency (“DECA”) within the Minister of Defense. We currently operate under an export license issued pursuant to the Israeli encryption control regime. Under this this regime our existing licenses prohibit us from exporting some of our products to customers in certain countries and requires us to obtain the consent of DECA to export some of our products to customers in certain other countries. Our failure to comply could subject us to financial penalties and restrictions on how we market and sell our products, each of which could materially adversely impact our revenue and profits, and harm our reputation. On November 18, 2025, the Israeli Minister of Defense signed an order repealing the current encryption control regime and adopting a new regime. The new regime becomes effective on March 18, 2026. We believe that under this order our current license should remain valid until September 2027. The new regime strictly applied could have the effect of subjecting some of our exports to a licensing requirement from DECA and to a lesser extent from the Ministry of Economy. We are currently in discussions with representatives of DECA and the Ministry of Economy regarding the possibility of continuing our export activities consistent with our practices under our current license, however there is no certainty with respect to the results of such discussions. If we are unable to achieve this outcome, we 32 Table of Content would likely need to adapt our licensing, marketing and export practices to accommodate this regulatory change, which would increase our expenses and may cause delays in sales and the loss of customers. This could materially adversely impact our revenue and profits, and harm our reputation. For more information, see Part 1, Item 4.B. Business Overview – Regulations – Export Controls. We are subject to export laws, regulations and governmental trade controls, and any noncompliance with these laws could negatively impact our operating results. Various countries regulate the export and import of certain encryption solutions and technology including cryptography or cryptanalytic capabilities, and have enacted laws that could limit our ability to distribute our solutions or could limit our customers’ ability to use our solutions in those countries. Any new export restrictions, new import restrictions, new legislation, changes in economic sanctions, or shifting approaches in the enforcement or scope of existing regulations, or in the countries, persons, or technologies targeted by such regulations, could result in decreased use of our products by existing customers, declining adoption of our products by new customers, limitation of our expansion into new markets, and decreased revenue and potential revenue growth. We have adopted policies and procedures that are intended to restrict sales to countries subject to U.S. and Israeli sanctions and export restrictions and to designated entities and individuals. Our solutions and technologies could be exported or re-exported to, or eventually be used by, these sanctioned targets due to circumvention of restrictions by customers, resellers or others, despite the contractual undertakings by which they are bound that prohibit them from exporting or reselling to any unauthorized customer, and any such export, re-export or use, could have negative consequences, including government investigations, penalties and reputational harm. Differing regulatory and legal requirements and the possible enactment of additional regulations or restrictions on the use, import, export or re-export of our solutions or the provision of services, delay, restrict, or prevent the sale or use of our solutions in some jurisdictions. If we or our business partners or counterparties, including licensors and licensees, prime contractors, subcontractors, sublicensors, vendors, customers, shipping partners, or contractors, fail to obtain appropriate import, export, or re-export licenses or permits, notwithstanding regulatory requirements or contractual commitments to do so, or if we fail to secure such contractual commitments where necessary, we may also be adversely affected, through reputational harm as well as other negative consequences, including government investigations and penalties. These laws and regulations are subject to change over time and thus we must continue to monitor and dedicate resources to ensure continued compliance. Although we take precautions to prevent our solutions from being provided in violation of such laws, the software could be provided inadvertently in violation of such laws, despite the precautions we take. Non-compliance with applicable regulations or requirements could, depending on the severity of the violation, subject us to investigations, sanctions, enforcement actions, disgorgement of profits, fines, damages, civil and criminal penalties, or injunctions. If any of the foregoing actions are imposed on us, or if we do not prevail in any possible civil or criminal litigation, in each case, for sufficiently serious violations, our business, operating results, and financial condition could be materially adversely affected. Our business is subject to complex and evolving U.S. and non-U.S. laws and regulations regarding privacy, data protection and security, technology protection, AI and other matters. Many of these laws and regulations are subject to change and uncertain interpretation, and could result in claims, changes to our business practices, monetary penalties, increased cost of operations, or otherwise harm our business. Our products are mostly used as an on-premise solution and are generally operated by our customers without our involvement. Nevertheless, we may occasionally have brief and limited access to customer 33 Table of Content data as a result of our technical support function or as a result of operating our SaaS-based solutions or serving as an outsourced lab for the extraction of data from devices that are sent to us by our customers. Given the global nature of our operations, we are subject to a variety of local, state, national, and international laws and directives and regulations related to privacy and data protection, data security, data storage and retention, data transfer and deletion, and technology protection. These laws include the following: •The European General Data Protection Regulation (“GDPR”) and the equivalent UK legislation. •U.S. state and federal laws, including the California Consumer Privacy Act (CCPA) and follow-on legislation in the California Privacy Rights Act (CPRA). •The Israeli Privacy Protection Law, 1981, along with its regulations such as the Israeli Privacy Protection Regulations (Data Security) 2017 •The Australian Privacy Act of 1988 and Canada’s Personal Information Protection and Electronic Documents Act, or PIPEDA, and various related provincial laws such as Quebec’s Law 25, as well as Canada’s Anti-Spam Legislation, or CASL. International data protection, data security, privacy, and other laws and regulations can impose different obligations or be more restrictive than those in the United States. Some of these laws and regulations include a private right of action or be enforced by government entities, are constantly evolving and can be subject to significant change, and they are likely to continue to develop and evolve for the foreseeable future. In addition, the application, interpretation, and enforcement of these laws and regulations are often uncertain, particularly in the new and rapidly evolving software and technology industry in which we operate, and may be interpreted and applied inconsistently from country to country and differently with our current policies and practices. Since our products and services are regularly used by law enforcement agencies, our customers may decide to store investigative data that may include sensitive information and PII using our SaaS-based solutions. Law enforcement agencies are often subject to specific laws and regulations pertaining to their field of activity. Such laws may impose additional data protection, security and other obligations and restrictions which could potentially apply to us or to our products and services, thereby further heightening our compliance obligations and potentially the costs and expenses. Each of these legislative actions may add additional complexity, variation in requirements, restrictions and potential legal risk, require additional investment in resources to compliance programs, and could impact strategies and availability of previously useful data and could result in increased compliance costs and/or changes in business practices and policies. These developments may require us to review and amend the legal mechanisms by which we make and, or, receive personal data transfers from other countries to Israel. As data protection regulators issue further guidance on personal data export mechanisms, including circumstances where the standard contractual clauses cannot be used, and/or start taking enforcement action, we could suffer additional costs, complaints and/or regulatory investigations or fines, and/or if we are otherwise unable to transfer personal data between and among countries and regions in which we operate, it could affect the manner in which we provide our services, the geographical location or segregation of our relevant systems and operations, and could adversely affect our financial results. These existing and proposed laws and regulations can be costly to comply with and can make our suite of solutions less effective or valuable, delay or impede the development of new solutions, result in negative publicity, increase our operating costs, require us to modify our data handling practices, limit our operations, impose substantial fines and penalties, require significant management time and attention, or put our data or technology at risk. Any failure or perceived failure by us or our suite of solutions to comply with applicable laws, regulations, directives, policies, industry standards, or legal obligations relating to privacy, data protection, or information security, or any security incident that results in loss of or the unauthorized access to, or acquisition, use, release, or transfer of, personal information, personal data, or other customer or sensitive data or information may result in governmental investigations, inquiries, enforcement actions and prosecutions, private claims and litigation, indemnification or other 34 Table of Content contractual obligations, other remedies, including fines or demands that we modify or cease existing business practices, or adverse publicity, and related costs and liabilities, which could significantly and adversely affect our business, reputation and results of operations. For more information, see Part 1, Item 4.B. Business Overview – Regulations – Data Privacy. We may in the future become involved in legal, regulatory, or administrative inquiries and proceedings, and unfavorable outcomes in litigation or other of these matters could negatively impact our business, financial conditions, and results of operations. From time to time, we receive formal and informal inquiries from governmental agencies and regulators regarding our compliance with laws and regulations or otherwise relating to our business or transactions. We may also become subject to claims, lawsuits, proceedings and inquiries which could involve labor and employment disputes, discrimination and harassment allegations, commercial disputes, intellectual property rights (including patent, trademark, copyright, trade secret, and other proprietary rights), class actions, general contract, tort, or defamation, data privacy rights, antitrust concerns, common law fraud, government regulation, compliance, alleged federal and state securities and “blue sky” law violations or other investor related questions. Derivative claims, lawsuits, and proceedings, which may, from time to time, be asserted against our directors by our shareholders, could involve breach of fiduciary duty, breach of duty of loyalty, failure of oversight, corporate waste claims, and other matters. For example, a former consultant has brought a number of claims against us and a number of our former director and officers. These claims could lead to reputational harm and diversion of resources and management’s attention from our primary business operations. In addition, our business and results may be adversely affected by the outcome of currently pending and any future legal, regulatory, and/or administrative claims or proceedings, including through monetary damages or injunctive relief. Over the last several years, lawsuits have been filed against cyber-related companies by large multinationals that claim that their terms of use or intellectual property have been violated and breached by the activities of the cyber companies. While we are not a cyber company, such a risk could potentially also apply to us and our solutions. The number and significance of our legal disputes and inquiries may increase as we continue to grow larger, as our business has expanded in customer count and as our suite of solutions becomes more complex. Additionally, if customers fail to pay us under the terms of our agreements, we may be adversely affected due to the cost of enforcing the terms of our contracts through litigation. Litigation or other proceedings can be expensive and time consuming and can divert our resources and management’s attention from our primary business operations. The results of our litigation also cannot be predicted with certainty. If we are unable to prevail in litigation, we could incur payments of substantial monetary damages or fines, or undesirable changes to our suite of solutions or business practices, and accordingly, our business, financial condition, or results of operations could be materially and adversely affected. Furthermore, if we accrue a loss contingency for pending litigation and determine that it is probable, any disclosures, estimates, and reserves we reflect in our financial statements with regard to these matters may not reflect the ultimate disposition or financial impact of litigation or other such matters. These proceedings could also result in negative publicity, which could harm customer and public perception of our business, regardless of whether the allegations are valid or whether we are ultimately found liable. Although we have limitation of liability provisions in our standard software licensing and service agreement terms and conditions, these provisions may not be enforceable in some circumstances, may vary in levels of protection across our agreements, or may not fully or effectively protect us from such claims and related liabilities and costs. We generally provide a warranty for our software and hardware solutions in our agreements. In the event that there is a failure of warranties in such agreements, we are generally obligated to replace or correct the product to conform to the warranty provision as set forth in the applicable agreement, or, if we are unable to do so, the customer is entitled to seek a refund of the purchase price of the product and service. The sale and support of our solutions also entail the risk of product liability claims. We maintain errors and omissions insurance to protect against certain claims associated with the use of our solutions, but our insurance coverage may not adequately cover any claim 35 Table of Content asserted against us. In addition, even claims that ultimately are unsuccessful could result in our expenditure of funds in litigation and divert management’s time and other resources. Failure to comply with laws, regulations, or contractual provisions applicable to our business could cause us to lose government customers or our ability to contract with the U.S. and other governments. The majority of our customers are government and state owned agencies, each with their own specific guidelines and compliance requirements for their government contracts. For example, our U.S. government business is subject to specific procurement regulations with numerous compliance requirements. In particular, we must comply with laws, regulations, and contractual provisions relating to the formation, administration, and performance of government contracts and inclusion on government contract vehicles, which affect how we and our partners do business with government agencies. These requirements, although customary in government contracting in the U.S., increase our performance and compliance costs. These costs may increase in the future, thereby reducing our margins, which could have an adverse effect on our financial condition. Moreover, in the United States, government contracts are subject to oversight audits by government representatives. Such audits could result in adjustments to our contracts. As an example, for contracts covered by the Cost Accounting Standards, any costs found to be improperly allocated to a specific contract may not be allowed, and such costs already reimbursed may have to be refunded. In addition, as a result of actual or perceived non-compliance with government contracting laws, regulations, or contractual provisions, we may be subject to other audits and internal investigations which may prove costly to our business financially and divert management’s attention and time. Among the causes for debarment are violations of various laws or policies, including those related to procurement integrity, export control, U.S. government security regulations, employment practices, protection of criminal justice data, protection of the environment, accuracy of records, proper recording of costs, foreign corruption, Trade Agreements Act, Buy America Act, and the False Claims Act. Contracts with the federal U.S. federal government may be terminated for convenience by the government at any time. Furthermore, regulatory requirements imposed by governments other than the United States may be more stringent and non-compliance may subject us as well as to investigations, proceedings, sanctions, or other consequences from those governments, as well as, in some cases, allow such governments to terminate contracts for convenience at any time. These consequences remain uncertain because of the dynamic nature of governmental action and responses. The laws and regulations applicable to each of our contracts may impose other added costs on our business, and failure to comply with these or other applicable regulations and requirements, including non-compliance in the past, could lead to claims for damages from our channel partners, penalties, and termination of contracts and suspension or debarment from government contracting for a period of time with government agencies. Any such damages, penalties, disruption, or limitation in our ability to do business with a government could adversely impact, and could have a material adverse effect on, our business, results of operations, financial condition, public perception, and growth prospects. We are subject to anti-corruption, anti-bribery, and similar laws, and non-compliance with such laws can subject us to criminal penalties or significant fines, harm our reputation, and significantly adversely affect our business, financial condition, results of operations, and growth prospects. We are and will be subject to anti-corruption, anti-bribery, anti-money laundering and financial and economic sanctions laws and regulations in various jurisdictions in which we conduct or in the future may conduct activities, including the Foreign Corrupt Practices Act (the “FCPA”), the U.K. Bribery Act 2010, and other domestic or foreign anti-corruption laws and regulations. The FCPA and the U.K. Bribery Act 2010 prohibit us and our officers, directors, employees and business partners acting on our behalf, including agents and intermediaries, from corruptly offering, promising, authorizing or providing 36 Table of Content anything of value to a “foreign official” for the purposes of influencing official decisions or obtaining or retaining business or otherwise obtaining favorable treatment. The FCPA also requires companies to make and keep books, records and accounts that accurately reflect transactions and dispositions of assets and to maintain a system of adequate internal accounting controls. The U.K. Bribery Act also prohibits non-governmental “commercial” bribery and soliciting or accepting bribes. A violation of these laws or regulations could materially adversely affect our business, results of operations, financial condition and reputation. Non-compliance with anti-corruption, anti-bribery, or similar laws could subject us to whistleblower complaints, adverse media coverage, investigations, and severe administrative, civil and criminal penalties, collateral consequences, remedial measures and legal expenses, all of which could materially and adversely affect our business, results of operations, financial condition and reputation. In addition, changes in economic sanctions laws in the future could adversely impact our business and an investment in our securities. Risks Relating to Cellebrite’s Incorporation and Location in Israel Conditions in Israel, including Israel’s conflicts with Hamas and other terrorist organizations in the region, as well as political and economic instability, may adversely affect our operations and limit our ability to market our products, which would lead to a decrease in revenues. We are incorporated under Israeli law, and many of our employees, including many of our management members, operate from our principal office and other facilities located in Israel. Furthermore, many of our employees, officers and directors are residents of Israel. We also operate a small assembly facility in Israel. Accordingly, our business and operations are directly affected by economic, political, geopolitical, and military conditions in Israel and the surrounding region. Since its establishment in 1948, the State of Israel has been subject to ongoing security concerns and challenges, as well as armed conflicts with its neighbors. Most recently, on October 7, 2023, Hamas, a terrorist group, launched an unprecedented terror attack on Israel from the Gaza Strip. Following the October 7th attacks, Israel declared war against Hamas and since then, Israel has been engaged in military conflicts with Hamas, Hezbollah, a terrorist organization based in Lebanon, and Iran, both directly and through proxies. In 2026, tensions between Israel and Iran escalated into another direct military conflict. Israel, United States, and Iran commenced a series of attacks and counterattacks. While there is hope talks among the parties will resume along with a ceasefire, it is not clear when an agreement will be reached and if an agreement will be upheld. The situation remains volatile, with the potential for escalation into a broader regional conflict, and future developments are unpredictable in the region. Actual or perceived political or security instability in Israel, or changes in the political environment, could adversely affect the Israeli economy and, in turn, our business, financial condition, results of operations and prospects. Hostilities and regional tensions may cause damage to private and public facilities, infrastructure, utilities and telecommunications networks, and may disrupt our operations and supply chains. In addition, Israeli organizations, government agencies and companies have been subject to extensive cyber attacks. This could lead to increased costs, risks to employee safety, and challenges to business continuity, with potential financial losses. Our commercial insurance does not cover losses that may occur as a result of events associated with war and terrorism. Although the Israeli government currently covers the reinstatement value of certain direct damages that are caused by terrorist attacks or acts of war, we cannot assure you that such government coverage will be maintained or that it will sufficiently cover our potential damages. Any losses or damages incurred by us could have a material adverse effect on our business. In connection with armed conflicts and security events, Israeli military reservists may be called up for service, including for extended periods. Some of our employees have been and may in the future be called into active military duty, and their absence may materially and adversely affect our ability to conduct our operations 37 Table of Content In addition, the State of Israel and Israeli companies have been subjected to economic boycotts. Several countries still restrict business with the State of Israel and with Israeli companies. These restrictive laws and policies may have an adverse impact on our operating results, financial condition or the expansion of our business. Political conditions within Israel may affect our operations. The Israeli government has pursued, and may continue to pursue, changes to Israel's judicial system, which has contributed to uncertainty and could lead to political instability or civil unrest. Any such developments could adversely affect the business environment in Israel and our business and operations. It may be difficult to enforce a U.S. judgment against us, and certain our officers and directors in Israel or the United States, or to assert U.S. securities laws claims in Israel or serve process on our officers and directors or experts. Service of process upon us or our non-U.S. resident directors and officers and enforcement of judgments obtained in the United States against us or our non-U.S. our directors and executive officers may be difficult to obtain within the United States. We have been informed by our legal counsel in Israel that it may be difficult to assert claims under U.S. securities laws in original actions instituted in Israel or obtain a judgment based on the civil liability provisions of U.S. federal securities laws. Israeli courts may refuse to hear a claim based on a violation of U.S. securities laws against us or our non-U.S. officers and directors because Israel may not be the most appropriate forum to bring such a claim. In addition, even if an Israeli court agrees to hear a claim, it may determine that Israeli law and not U.S. law is applicable to the claim. If U.S. law is found to be applicable, the content of applicable U.S. law must be proved as a fact, typically through an expert witness, which can be a time-consuming and costly process. Certain matters of procedure will also be governed by Israeli law. There is little binding case law in Israel addressing the matters described above. Israeli courts might not enforce judgments rendered outside of Israel, which may make it difficult to collect on judgments rendered outside of Israel against us or our non-U.S. officers and directors. Moreover, an Israeli court will not enforce a non-Israeli judgment if it was given in a state whose laws do not provide for the enforcement of judgments of Israeli courts (subject to exceptional cases), if its enforcement is likely to prejudice the sovereignty or security of the State of Israel, if it was obtained by fraud or in the absence of due process, if it is at variance with another valid judgment that was given in the same matter between the same parties, or if a suit in the same matter between the same parties was pending before a court or tribunal in Israel at the time the foreign action was brought. 38 Table of Content The rights and responsibilities of our shareholders are governed by Israeli law, which may differ in some respects from the rights and responsibilities of shareholders of U.S. corporations. We are incorporated under Israeli law. The rights and responsibilities of holders of Ordinary Shares are governed by our amended and restated articles of association (the “Articles”) and the Israeli Companies Law (the “Companies Law”). These rights and responsibilities differ in some respects from the rights and responsibilities of shareholders in typical U.S. corporations. In particular, pursuant to the Companies Law, each shareholder of an Israeli company has to act in good faith and in a customary manner in exercising his, her or its rights and fulfilling his, her or its obligations toward the Company and other shareholders and to refrain from abusing his, her or its power in the Company, including, among other things, in voting at the general meeting of shareholders, on one of the following: (i) amendments to a company’s articles of association, (ii) increases in a company’s authorized share capital, (iii) mergers and (iv) certain transactions requiring shareholders’ approval under the Companies Law. In addition, a controlling shareholder of an Israeli company or a shareholder who knows that it possesses the power to determine the outcome of a shareholder vote or who has the power according to the Articles to appoint or prevent the appointment of a director or officer in the Company, or has other powers toward the Company according to the Articles, has a duty of fairness toward the Company. However, Israeli law does not define the substance of this duty of fairness. There is little case law available to assist in understanding the implications of these provisions that govern shareholder behavior. Provisions in the Articles may have the effect of discouraging lawsuits against us and our directors and officers. Under the Articles, the competent courts of Tel Aviv, Israel are the exclusive forum for (i) any derivative action or proceeding brought on behalf of Cellebrite, (ii) any action asserting a claim of breach of fiduciary duty or a claim of breach of the duty of loyalty owed by any of Cellebrite’s directors, officers or other employees or our shareholders, or (iii) any action asserting a claim arising pursuant to any provision of the Companies Law or the Israeli Securities Law. Additionally, unless we consent in writing to the selection of an alternative forum, the U.S. federal courts shall be the exclusive forum for the resolution of any complaint asserting a cause of action arising under the Securities Act of 1933, as amended (the “Securities Act”) against us or any of our directors, officers, other employees or agents. Section 22 of the Securities Act, however, creates concurrent jurisdiction for U.S. federal and state courts over all suits brought to enforce any duty or liability created by the Securities Act or the rules and regulations thereunder. Accordingly, there is uncertainty as to whether a court would enforce such provisions, and the enforceability of similar choice of forum provisions in other companies’ charter documents has been challenged in legal proceedings. While Delaware and certain U.S. courts have determined that such exclusive forum provisions are facially valid, a shareholder may nevertheless seek to bring a claim in a venue other than those designated in the exclusive forum provisions, and there can be no assurance that such provisions will be enforced by a court in those other jurisdictions. Any person or entity purchasing or otherwise acquiring any interest in our securities shall be deemed to have notice of and consented to these provisions; however, we note that investors cannot waive compliance with the federal securities laws and the rules and regulations thereunder. Section 27 of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), creates exclusive federal jurisdiction over all suits brought to enforce any duty or liability created by the Exchange Act or the rules and regulations thereunder. Accordingly, notwithstanding the foregoing, the Articles provide that the exclusive forum provision will not apply to suits brought to enforce a duty or liability created by the Exchange Act or any other claim for which the federal courts have exclusive jurisdiction. 39 Table of Content These exclusive forum provisions may limit a shareholders ability to bring a claim in a judicial forum of its choosing for disputes with us or our directors or other employees which may discourage lawsuits against us, our directors, officers and employees. Risks Relating to an Investment in our Securities Future issuances of Ordinary Shares by us or resales of our Ordinary Shares may cause the market price of the Ordinary Shares to drop significantly, even if our business is doing well. We have entered into an Investor Rights Agreement pursuant to which we have registered for resale the shares held by SUNCORPORATION, our largest shareholder, TWC Tech Holdings II, LLC (“TWC”), and the other parties thereto. See the section of this Annual Report titled “Part I, Item 7. Major Shareholders and Related Party Transactions — Related Party Transactions.”. SUNCORPORATION and TWC are entitled to request that we effect an underwritten offering of their shares and they are entitled to include their shares in underwritten offerings that we undertake, subject to first cutback. A decision by these shareholders to sell shares, whether in an underwritten offering or otherwise, could adversely impact the price of our Ordinary Shares. In addition, 1,500,000 Ordinary Shares held by TWC are “Restricted Sponsor Shares” and are eligible to vest if at any time during the Price Adjustment Period (a period of seven years from the Closing, ending on August 29, 2028, as defined in the Merger Agreement (as defined below)) the price of our Ordinary Shares is greater than $30.00 over any 20 trading days within any 30 trading day period (a “Restricted Sponsor Share Triggering Event”). This follows the previous vesting of 6,000,000 Ordinary Shares following the achievement of prior price targets. We have also historically used, and continue to use, our Ordinary Shares as a means of both rewarding our employees, non-employee directors, and consultants and aligning their interests with those of our shareholders. As of December 31, 2025, 12,624,891 Ordinary Shares were subject to outstanding awards (consisting of outstanding options to purchase 4,605,544 Ordinary Shares and 8,019,347 Ordinary Shares underlying unvested restricted share units (“RSUs”)) granted to our and our affiliates’ respective employees, non-employee directors, consultants and former employees under our equity incentive plans. Additionally, 17,898,577 Ordinary Shares were available for future grant under the 2021 Plan and 2,448,431 Ordinary Shares were available for grant under our equity incentive plans or for future purchase under our ESPP, subject to increase under the evergreens terms of certain of those plans. All of the underlying Ordinary Shares are registered on Form S-8 for immediate sale or resale. Thus, Ordinary Shares granted or issued under our equity incentive plans will, subject to vesting provisions, lock-up restrictions, and applicable Rule 144 volume limitations, be available for sale in the open market immediately upon registration. In a registered offering of securities pursuant to the Securities Act (including via the registration statement on Form S-8) or otherwise in accordance with Rule 144 under the Securities Act, Cellebrite shareholders may sell large amounts of Ordinary Shares in the open market or in privately negotiated transactions, which could have the effect of increasing the volatility in the trading price of the Ordinary Shares or putting significant downward pressure on the price of the Ordinary Shares. Further, sales of Ordinary Shares upon expiration of the applicable lockup period could encourage short sales by market participants. Generally, short selling means selling a security, contract or commodity not owned by the seller. The seller is committed to eventually purchase the financial instrument previously sold. Short sales are used to capitalize on an expected decline in the security’s price. As such, short sales of Ordinary Shares could have a tendency to depress the price of the Ordinary Shares, which could increase the potential for short sales. 40 Table of Content We cannot predict the size of future issuances by us or resales by others of Ordinary Shares or the effect, if any, that such future issuances and sales of Ordinary Shares will have on the market price of the Ordinary Shares. Sales of substantial amounts of Ordinary Shares (including those shares issued in connection with the Merger (as defined below)), or the perception that such sales could occur, may materially and adversely affect prevailing market prices of Ordinary Shares. As a “foreign private issuer” under applicable securities laws and regulations, Cellebrite is permitted to, and may, file less or different information with the U.S. Securities and Exchange Commission (the “SEC”) than a company incorporated in the United States, and will follow certain home country governance practices in lieu of certain Nasdaq requirements applicable to U.S. issuers. We are considered a “foreign private issuer” under the Exchange Act and are therefore exempt from certain rules under the Exchange Act. Moreover, we are not required to file periodic reports and financial statements with the SEC as frequently or within the same time frames as U.S. issuers with securities registered under the Exchange Act, and are not subject to the rules prescribing the furnishing and content of proxy statements. We are not required to comply with Regulation FD, which imposes restrictions on the selective disclosure of material information to shareholders although our investor relations practices are focused on complying with Regulation FD. Recently enacted U.S. legislation will require our directors and officers to make insider reports under Section 16(a) of the Exchange Act, effective March 18, 2026. Our principal shareholders continue to remain exempt from the reporting requirements under Section 16(a) of the Exchange Act and our directors, officers and principal shareholders continue to remain exempt from the short-swing profit recovery provisions contained in Section 16(b) of the Exchange Act. Accordingly, if you own our securities, you may receive less or different information about us than that you would receive about a U.S. issuer. In addition, as a “foreign private issuer” whose securities are listed on Nasdaq, we are permitted to follow certain home country corporate governance practices in lieu of certain Nasdaq requirements. A “foreign private issuer” must disclose in its annual reports filed with the SEC each Nasdaq requirement with which it does not comply, followed by a description of its applicable home country practice. We currently intend to follow the corporate governance requirements of Nasdaq. However, we cannot make any assurances that it will continue to follow such corporate governance requirements in the future, and may therefore in the future, rely on available Nasdaq exemptions that would allow us to follow its home country practice. Unlike the requirements of Nasdaq, there are currently no mandatory corporate governance requirements in Israel that would require us to (i) have a majority of its board of directors be independent, (ii) establish a nominating/governance committee, or (iii) hold regular executive sessions where only independent directors may be present. Such Israeli home country practices may afford less protection to holders of our securities. We currently rely on this “foreign private issuer exemption” only with respect to the quorum requirement for shareholder meetings and the requirement regarding distribution of annual and interim reports. For more information, see “Part II, Item 16G. Corporate Governance.” We otherwise comply with and intend to continue to comply with the rules generally applicable to U.S. domestic companies listed on Nasdaq. In addition, with respect to SEC rules, we expect to issue interim quarterly financial information publicly and to furnish them to the SEC under cover of Form 6-K. We may, however, in the future decide to rely upon the “foreign private issuer exemption” for purposes of opting out of some or all of the other Nasdaq corporate governance rules. 41 Table of Content We could lose its status as a “foreign private issuer” under applicable securities laws and regulations if more than 50% of our outstanding voting securities become directly or indirectly held of record by U.S. holders and any one of the following is true: (i) the majority of our directors or executive officers are U.S. citizens or residents; (ii) more than 50% of our assets are located in the United States; or (iii) our business is administered principally in the United States. If we lose its status as a “foreign private issuer” in the future, it will no longer be exempt from the rules described above and, among other things, will be required to file periodic reports and annual and quarterly financial statements as if it were a company incorporated in the United States. If this were to happen, we would likely incur substantial costs in fulfilling these additional regulatory requirements and members of our management would likely have to divert time and resources from other responsibilities to ensuring these additional regulatory requirements are fulfilled. Our largest shareholder, SUNCORPORATION, is a Japanese public company and currently a holder of more than 42% of Cellebrite’s outstanding shares. As of February 23, 2026, SUNCORPORATION (TSE JASDAQ: 6736), a Japanese public company, beneficially owns 42.5% of our Ordinary Shares. Therefore, SUNCORPORATION has significant influence on the outcome of all decisions at our shareholders’ meetings including: •the election of our board of directors; •amendments to our articles of association; and •our ability to enter into a change of control transaction. SUNCORPORATION’s decisions as to how it votes its Ordinary Shares may be contrary to the expectations or preferences of our other shareholders. The influence exerted by SUNCORPORATION may limit the ability of our shareholders to influence corporate matters and could also discourage other companies from pursuing any potential merger, takeover, or other change of control transactions with us. Further, SUNCORPORATION is a controlling shareholder which may in the future control elections to our board of directors and, therefore may have significant influence over our business and policies. 42 Table of Content Risks Related to Ownership of the Ordinary Shares Our share price has been and will likely continue to be volatile, and shareholders may lose all or part of their investment. Our shareholders have sold and may continue to sell their shares in the public market. The sales of significant amounts of our shares, or the perception in the market that this will occur, may decrease the market price of our shares. For more information, see “Risks Relating to an Investment in our Securities— Future issuances of Ordinary Shares by us or resales of our Ordinary Shares may cause the market price of the Ordinary Shares to drop significantly, even if our business is doing well.” Our share price may also be volatile for other reasons, including: •announcements by us or our competitors regarding, among other things, strategic changes, new products, product enhancements or technological advances, acquisitions, major transactions, significant litigation or regulatory matters, stock repurchases, or management changes; •analyst reports or press coverage of such reports, including with respect to changes in recommendations or earnings estimates or growth rates by financial analysts, changes in investors’ or analysts’ valuation measures for our securities, our security solutions and customers, speculation regarding strategy or mergers and acquisitions (“M&A”), or market trends unrelated to our performance; •stock sales by us or our directors, officers, or other significant holders, or stock repurchases by us; •hedging or arbitrage trading activity by third parties; •actual or anticipated fluctuations in our results of operations; •market conditions in our industry and changes in the estimation of the future growth and size of our markets; •real or perceived future dilution risk; •meaningful M&A activities, actual or anticipated, or lack thereof; •the trading volume of our ordinary shares; and •general economic, regulatory, political and market conditions. In addition, the stock markets have experienced extreme price and volume fluctuations. Broad market and industry factors may materially harm the market price of our ordinary shares, regardless of our operating performance. In the past, following periods of volatility in the market price of a company’s securities, securities class action litigation has often been instituted against that company. Such lawsuits could result in substantial costs and divert management’s attention and resources, which could adversely affect our business. 43 Table of Content The U.S. Internal Revenue Service (“IRS”) may not agree that Cellebrite should be treated as a non-U.S. corporation for U.S. federal income tax purposes. Although Cellebrite is incorporated and tax resident in Israel, the IRS may assert that it should be treated as a U.S. corporation (and therefore a U.S. tax resident) for U.S. federal income tax purposes pursuant to Section 7874 (“Section 7874”) of the Internal Revenue Code of 1986, as amended (the “Code”). For U.S. federal income tax purposes, a corporation is generally considered a U.S. ”domestic” corporation (or U.S. tax resident) if it is organized in the United States, and a corporation is generally considered a “foreign” corporation (or non-U.S. tax resident) if it is not a U.S. corporation. Because Cellebrite is an entity incorporated and tax resident in Israel, it would generally be classified as a foreign corporation (or non-U.S. tax resident) under these rules. Section 7874 provides an exception under which a foreign incorporated and foreign tax resident entity may, in certain circumstances, be treated as a U.S. corporation for U.S. federal income tax purposes. As more fully described in the section titled “Material U.S. Federal Income Tax Considerations — U.S. Federal Income Tax Treatment of Cellebrite — Tax Residence of Cellebrite for U.S. Federal Income Tax Purposes”, based on the terms of the Merger and the rules for determining share ownership under Section 7874 and the Section 7874 Regulations, Cellebrite has not been and is not intended to be treated as a U.S. corporation for U.S. federal income tax purposes under Section 7874 since the Merger. However, the application of Section 7874 is complex, is subject to detailed regulations (the application of which is uncertain in various respects, could be impacted by changes in such U.S. Treasury regulations with possible retroactive effect), and is subject to certain factual uncertainties. Accordingly, potential application of Section 7874 is inherently uncertain and there can be no assurance that the IRS will not challenge the status of Cellebrite as a foreign corporation under Section 7874 or that such challenge would not be sustained by a court. If the IRS were to successfully challenge Cellebrite’s status as a foreign corporation for U.S. federal income tax purposes under Section 7874, Cellebrite and certain Cellebrite shareholders would be subject to significant adverse tax consequences, including a higher effective corporate income tax rate on Cellebrite and future withholding taxes on certain Cellebrite shareholders, depending on the application of any income tax treaty that might apply to reduce such withholding taxes. In particular, holders of Ordinary Shares and Warrants would be treated as holders of stock and warrants of a U.S. corporation. See “Part I, Item 10. Additional Information—E. Material Taxation— Material U.S. Federal Income Tax Considerations—U.S. Federal Income Tax Treatment of Cellebrite—Tax Residence of Cellebrite for U.S. Federal Income Tax Purposes” for a more detailed discussion of the application of Section 7874 to the Merger. Investors in Cellebrite should consult their own advisors regarding the application of Section 7874 to the Merger. Section 7874 may limit the ability of TWC to use certain tax attributes, increase Cellebrite’s U.S. affiliates’ U.S. taxable income or have other adverse consequences to Cellebrite and Cellebrite’s shareholders. Following the acquisition of a U.S. corporation by a foreign corporation, Section 7874 can limit the ability of the acquired U.S. corporation and its U.S. affiliates to use U.S. tax attributes (including net operating losses and certain tax credits) to offset U.S. taxable income resulting from certain transactions, as well as result in certain other adverse tax consequences, even if the acquiring foreign corporation is respected as a foreign corporation for purposes of Section 7874. In general, if a foreign corporation acquires, directly or indirectly, substantially all of the properties held directly or indirectly by a U.S. corporation and after the acquisition, the former shareholders of the acquired U.S. corporation hold at least 60% (by either vote or value) but less than 80% (by vote and value) of the shares of the foreign acquiring corporation by reason of holding shares in the acquired U.S. corporation, subject to other requirements, certain adverse tax consequences under Section 7874 may apply. 44 Table of Content If these rules apply to the Merger, Cellebrite and certain of Cellebrite’s shareholders may be subject to adverse tax consequences including, but not limited to, restrictions on the use of tax attributes with respect to “inversion gain” recognized over a 10-year period following the transaction, disqualification of dividends paid from preferential “qualified dividend income” rates and the requirement that any U.S. corporation owned by Cellebrite include as “base erosion payments” that may be subject to a minimum U.S. federal income tax any amounts treated as reductions in gross income paid to certain related foreign persons. Furthermore, certain “disqualified individuals” (including officers and directors of a U.S. corporation) may be subject to an excise tax on certain stock-based compensation held thereby at a rate of 20%. As more fully described in the section titled “Material U.S. Federal Income Tax Considerations — U.S. Federal Income Tax Treatment of Cellebrite — Utilization of TWC’s Tax Attributes and Certain Other Adverse Tax Consequences to Cellebrite and Cellebrite’s Shareholders,” based on the terms of the Merger and the rules for determining share ownership under Section 7874 and the Section 7874 Regulations, Cellebrite is not intended to be subject to these rules under Section 7874 after the Merger. The above determination, however, is subject to detailed regulations (the application of which is uncertain in various respects and could be impacted by future changes in such U.S. Treasury regulations, with possible retroactive effect) and is subject to certain factual uncertainties. Accordingly, there can be no assurance that the IRS will not challenge whether Cellebrite is subject to the above rules or that such a challenge would not be sustained by a court. See “Part I, Item 10. Additional Information—E. Material Taxation — Material U.S. Federal Income Tax Considerations — Material U.S. Federal Income Tax Treatment of Cellebrite —Utilization of TWC’s Tax Attributes and Certain Other Adverse Tax Consequences to Cellebrite and Cellebrite’s Shareholders” for a more detailed discussion of the application of Section 7874 to the Merger. Investors in Cellebrite should consult their own advisors regarding the application of Section 7874 to the Merger. 45 Table of Content Risks Related to the Israeli Tax Treatment of Cellebrite and the Merger If we do not qualify for Israeli tax benefits, our effective tax rate on our business income and the Israeli withholding tax on distributions of dividends by us to our shareholders may be higher than expected. Cellebrite believes that it is currently entitled to claim certain tax benefits in Israel, including reduced corporate tax rates, reduced withholding tax rates with respect to dividend distributions and higher depreciation rates. These tax benefits require us to satisfy each tax year certain conditions that included in the provisions of Israeli tax laws. There can be no assurances that we will qualify for such tax benefits in any given year. If we do not qualify for such tax benefits, the effective Israeli tax rate on our business income and the withholding tax rate with respect to dividend that we will distribute to our shareholders may be higher than we expect. The enactment of legislation implementing changes in taxation of international business activities, the adoption of other corporate tax reform policies, or changes in tax legislation or policies could impact our future financial position and results of operations. There can be no assurance that our effective tax rate for the year ended December 31, 2025 will not change over time as a result of changes in corporate income tax rates or other changes in the tax laws the jurisdictions in which we operate. Any changes in tax laws could have an adverse impact on our financial results. Corporate tax reform, base-erosion efforts and tax transparency continue to be high priorities in many tax jurisdictions where we have business operations. As a result, policies regarding corporate income and other taxes in numerous jurisdictions are under heightened scrutiny and tax reform legislation is being proposed or enacted in a number of jurisdictions. In addition, there is growing pressure in many jurisdictions and from multinational organizations such as the Organization for Economic Cooperation and Development (OECD) and the EU to amend existing international taxation rules in order to align the tax regimes with current global business practices. Specifically, in October 2015, the OECD published its final package of measures for reform of the international tax rules as a product of its Base Erosion and Profit Shifting (BEPS) initiative, which was endorsed by the G20 finance ministers. Many of the initiatives in the BEPS package required and resulted in specific amendments to the domestic tax legislation of various jurisdictions and to existing tax treaties. We continuously monitor these developments. Although many of the BEPS measures have already been implemented or are currently being implemented globally (including, in certain cases, through adoption of the OECD’s “multilateral convention” (to which Israel is also a party) to effect changes to tax treaties which entered into force on July 1, 2018 and through the European Union’s “Anti Tax Avoidance” Directives), it is still difficult in some cases to assess to what extent these changes our tax liabilities in the jurisdictions in which we conduct our business or to what extent they may impact the way in which we conduct our business or our effective tax rate due to the unpredictability and interdependency of these potential changes. In January 2019 the OECD announced further work in continuation of the BEPS project, focusing on two “pillars”. On October 8, 2021, 136 countries approved a statement known as the OECD BEPS Inclusive Framework, which builds upon the OECD’s continuation of the BEPS project. The first pillar is focused on the allocation of taxing rights between countries for in-scope large multinational enterprises (with revenue in excess of Euro 20 billion and profitability of at least 10%) that sell goods and services into countries with little or no local physical presence. The second pillar is focused on developing a global minimum tax rate of at least 15 percent applicable to in-scope multinational enterprises (with revenue in excess of Euro 750 million). Israel is one of the 136 jurisdictions that has agreed in principle to the adoption of the global minimum tax rate. Given these developments, it is generally expected that tax authorities in various jurisdictions in which we operate may increase their audit activity and may seek to challenge some of the tax positions we have adopted. It is difficult to assess if and to what extent such challenges, if raised, might impact our effective 46 Table of Content tax rate. On December 15, 2022, Council of the EU unanimously adopted the EU Directive on Global Minimum Tax. In line with the above-mentioned global developments in international taxation, the state of Israel has recently enacted the Law for the Taxation of Multinational Enterprise Groups – 2025, implementing key aspects of the OECD’s Pillar Two framework. In particular, the legislation introduces a domestic minimum top-up tax (Qualified Domestic Minimum Top-Up Tax – QDMTT) generally applicable to Israeli entities that are part of multinational enterprise groups with consolidated annual revenues of at least EUR 750 million, with the objective of ensuring a minimum effective tax rate of 15% on profits attributable to activities in Israel and preventing the allocation of taxing rights to foreign jurisdictions under the Income Inclusion Rule or the Undertaxed Profits Rule. Based on the Company’s current forecasts, the Company does not expect its consolidated annual revenues to reach the EUR 750 million threshold in 2026; however, no assurance can be given that future changes in the Company’s business or growth trajectory will not result in the applicability of such legislation in any period. It is noted that the Israeli Ministry of Finance has published an additional draft as part of the 2026 Economic Plan, proposing a revised incentive regime for research and development activities in Israel, structured primarily as refundable or credit-based tax incentives designed to qualify under the OECD’s “qualified” incentive criteria in a Pillar Two environment. We may be required to pay Israeli taxes, including by way of withholding from our shareholders, as a result of the transactions contemplated by the Merger Agreement, and if we do not receive the Transaction Tax Ruling exempting the Indemnified TWC Parties from certain taxes we may be required to indemnify the Indemnified TWC Parties for such Israeli withholding tax liability. Pursuant to the Merger Agreement we have filed an application to receive the Transaction Tax Ruling (which was bifurcated to three separate applications) from the Israel Tax Authority, which seeks to determine (i) that none of the Indemnified TWC Parties (as defined in the Merger Agreement) are subject to Israeli tax with respect to receipt of Ordinary Shares and/or Warrants, (ii) the tax treatment of the issuance of the Price Adjustment Shares and the Additional Dividend (as defined in the Merger Agreement) for Israeli Tax purposes and (iii) that the Capital Restructuring (as defined in the Merger Agreement) is not subject to Israeli withholding Tax. We received a signed ruling regarding the Capital Restructuring and the distribution of funds from the trust account to the Company, as well as a signed ruling regarding the Additional Dividend. We withdrew the ruling applications with regards to the tax treatment of the issuance of the Price Adjustment Shares and the exemption of the Indemnified TWC Parties from Israeli tax with respect to receipt of Ordinary Shares and/or Warrants. We made an irrevocable written undertaking to fully indemnify and hold harmless (on a grossed up basis, to account for their related tax liability and for their Cellebrite holdings) the Indemnified TWC Parties from any Israeli tax actually incurred by such Indemnified TWC Parties which should have been exempted by the Transaction Tax Ruling (including from all costs and expenses, including reasonable attorney costs, associated with such tax, including in defending such matters). If an indemnification event will occur, our business results may be adversely affected. 47 Table of Content General Risk Factors Joint ventures, partnerships, and strategic alliances may have a material adverse effect on our business, results of operations and prospects. We intend to continue to enter into joint ventures, partnerships, and strategic alliances as part of our long-term business strategy. Joint ventures, partnerships, strategic alliances, and other similar arrangements involve significant investments of both time and resources, and there can be no assurances that they will be successful. They may present significant challenges and risks, including that they may not advance our business strategy, we may get an unsatisfactory return on our investment or lose some or all of our investment, they may distract management and divert resources from our core business, they may expose us to unexpected liabilities, or we may choose a partner that does not cooperate as we expect them to and that fails to meet its obligations or that has economic, business, or legal interests or goals that are inconsistent with ours. For example, we partner with various resellers who coordinate the provision of our solutions to the end customers. Also, for example, there is risk for termination of strategic or technology partnerships that complement or compose part of our offering; such terminations may impact our ability to successfully compete in the market. We believe these arrangements can offer strategic advantages, but they increase our dependence on third parties to achieve our objectives. Entry into certain joint ventures, partnerships, or strategic alliances now or in the future may be subject to government regulation, including review by U.S. or foreign government entities related to foreign direct investment. If a joint venture or similar arrangement were subject to regulatory review, such regulatory review might limit our ability to enter into the desired strategic alliance and thus our ability to carry out our long-term business strategy. As our joint ventures, partnerships, and strategic alliances come to an end or terminate, we have been, in some cases, unable to renew or replace them on comparable terms, or at all. Each of our agreements with resellers have terms of just one year, and so these agreements are frequently up for renewal or termination. When we enter into joint ventures, partnerships, and strategic alliances, our partners may be required to undertake some portion of sales, marketing, implementation solutions, engineering solutions, or software configuration that we would otherwise provide. In such cases, our partner may be less successful than we would have otherwise been absent the arrangement. In the event we enter into an arrangement with a particular partner, we may be less likely (or unable) to work with one or more direct competitors of our partner with which we would have worked absent the arrangement. We may have interests that are different from our partners and/or which may affect our ability to successfully collaborate with a given partner. Similarly, one or more of our partners in a joint venture, partnership, or strategic alliance may independently suffer a bankruptcy or other economic hardship that negatively affects its ability to continue as a going concern or successfully perform on its obligation under the arrangement. In addition, customer satisfaction with our solutions provided in connection with these arrangements may be less favorable than anticipated, negatively impacting anticipated revenue growth, margins and results of operations of arrangements in question. Further, some of our partners offer competing solutions or work with our competitors and some strategic partners have in the past and others may in the future be acquired by our competitors, resulting in the termination of the partnership. As a result of these and other factors, many of the companies with which we have joint ventures, partnerships, or strategic alliances may choose to pursue alternative technologies and develop alternative solutions in addition to or in lieu of our solutions, either on their own or in collaboration with others, including our competitors. If we are unsuccessful in establishing or maintaining our relationships with these partners, our ability to compete in a given marketplace or to grow our revenue would be impaired, and our results of operations may suffer. Even if we are successful in establishing and maintaining these relationships with our partners, we cannot assure you that these relationships will result in increased customer usage of our suite of solutions or increased revenue. Further, winding down joint ventures, partnerships, or other strategic alliances can result in additional costs, litigation, and negative publicity. Any of these events could adversely affect our business, financial condition, results of operations, and growth prospects. 48 Table of Content We have in the past and may in the future acquire or invest in companies and technologies, which may divert our management’s attention, and result in additional dilution to our shareholders. We may be unable to integrate acquired businesses and technologies successfully or achieve the expected benefits of such acquisitions or investments. As part of our business strategy, we have engaged in strategic transactions in the past and expect to evaluate and consider potential strategic transactions, including acquisitions of, or investments in, businesses, technologies, products, services and other assets in the future. In December 2025, we acquired Corellium, Inc., a leader in virtualization software for devices that rely on power-efficient Arm processors. The addition of Corellium further broadens Cellebrite’s offerings for both public and private sector customers. Past acquisitions, including the acquisition of Corellium, or any future acquisition, investment or business relationship in some cases have and may in the future result in unforeseen risks, operating difficulties and expenditures, including but not limited to the following: •An acquisition may negatively affect our financial results because it may require us to incur charges or assume substantial debt or other liabilities, may cause adverse tax consequences or unfavorable accounting treatment, may expose us to claims and disputes by third parties, including intellectual property claims and disputes, or may not generate sufficient financial return to offset additional costs and expenses related to the acquisition; •Potential goodwill impairment charges related to acquisitions; •Costs and potential difficulties associated with the requirement to test and assimilate the internal control processes of the acquired business; •We may encounter difficulties or unforeseen expenditures assimilating or integrating the businesses, technologies, infrastructure, solutions, personnel, or operations of the acquired companies, particularly if the key personnel of the acquired company choose not to work for us or if we are unable to retain key personnel, if their technology is not easily adapted to work with ours, or if we have difficulty retaining the customers of any acquired business due to changes in ownership, management, or otherwise; •We may not realize the expected benefits of the acquisition in a timely manner, if at all; •An acquisition may disrupt our ongoing business, divert resources, increase our expenses, and distract our management; •An acquisition may result in a delay or reduction of customer purchases for both us and the company acquired due to customer uncertainty about continuity and effectiveness of service from either company; •The potential impact on relationships with existing customers, vendors, and distributors as business partners as a result of acquiring another company or business that competes with or otherwise is incompatible with those existing relationships; •The potential that our due diligence of the acquired company or business does not identify significant problems or liabilities, or that we underestimate the costs and effects of identified liabilities; •Exposure to litigation or other claims in connection with, or inheritance of claims or litigation risk as a result of, an acquisition, including but not limited to claims from former employees, customers, or other third parties, which may differ from or be more significant than the risks our business faces; •We may encounter difficulties in, or may be unable to, successfully sell any acquired solutions; •An acquisition may involve the entry into geographic or business markets in which we have little or no prior experience or where competitors have stronger market positions; 49 Table of Content •An acquisition may require us to comply with additional laws and regulations, or to engage in substantial remediation efforts to cause the acquired company to comply with applicable laws or regulations, or result in liabilities resulting from the acquired company’s failure to comply with applicable laws or regulations; •If we incur debt to fund such acquisition, such debt may subject us to material restrictions on our ability to conduct our business as well as financial maintenance covenants; and •To the extent that we issue a significant amount of equity securities in connection with future acquisitions, existing shareholders may be diluted and earnings per share may decrease. The occurrence of any of these risks could have a material adverse effect on our business, results of operations, and financial condition. Moreover, we cannot assure you that we would not be exposed to unknown liabilities. Our international operations expose us to business, political and economic risks that could cause our operating results to suffer. We intend to continue to make efforts to increase our international operations and anticipate that international sales will continue to account for a significant portion of our revenue. These international operations are subject to certain risks and costs, including the difficulty and expense of administering business and compliance abroad, differences in business practices, compliance with domestic and foreign laws (including without limitation domestic and international import and export laws and regulations and the FCPA, including potential violations by acts of agents or other intermediaries), costs related to localizing solutions for foreign markets, costs related to translating and distributing software solutions in a timely manner, costs related to increased financial accounting and reporting burdens and complexities, longer sales and collection cycles for accounts receivables, failure of laws or courts to protect our intellectual property rights adequately, local competition, and economic or political instability and uncertainties, including inflation, recession, interest rate fluctuations and actual or anticipated military or geopolitical conflicts. In addition, regulatory limitations regarding the repatriation of earnings may adversely affect the transfer of cash earned from foreign operations. Significant international sales may also expose us to greater risk from political and economic instability, unexpected changes in Israeli, U.S. or other governmental policies concerning import and export of goods and technology, regulatory requirements, tariffs and other trade barriers. Economic downturns and geopolitical challenges in the Americas, EMEA or certain other parts of the world critical to our operations could cause our customers in or outside of those locations to reevaluate decisions to purchase our solutions or to delay or reduce their technology purchasing decisions, which could adversely impact our results of operations. Regional conflicts, such as Russia’s invasion of Ukraine, and measures taken in response thereto have created global security concerns that could have a lasting adverse impact on regional and global economies, and in turn, on our customers’ decision to purchase our products. Additionally, international earnings may be subject to taxation by more than one jurisdiction, which may materially adversely affect our effective tax rate. Finally, international expansion may be difficult, time consuming, and costly. These risks and their potential impacts may be exacerbated by to prolonged economic uncertainties of downturns. As a result, if revenue from international operations do not offset the expenses of establishing and maintaining foreign operations, our business, operating results and financial condition will suffer. 50 Table of Content If our goodwill or intangible assets become impaired, we may be required to record a significant charge to earnings. We have acquired and may acquire other companies and intangible assets, and we may not realize all the economic benefit from those acquisitions, which could cause an impairment of goodwill or intangibles. We review our amortizable intangible assets for impairment when events or changes in circumstances indicate the carrying value may not be recoverable. We test goodwill for impairment at least annually. If such goodwill is deemed to be impaired, an impairment loss equal to the amount by which the carrying amount exceeds the fair value of the assets would be recognized. Events which might indicate impairment include, but are not limited to, declines in stock price market capitalization or cash flows, adverse cost factors, deteriorating financial performance, strategic decisions made in response to economic, market and competitive conditions, the impact of the economic environment on us and our customer base, and/or relevant events such as changes in management, key personnel, litigation or customers. We may be required to record a significant charge in our financial statements during the period in which any impairment of our goodwill or intangible assets is determined, which would negatively affect our results of operations. Our provision for income taxes and effective income tax rate may vary significantly and may adversely affect our results of operations and cash resources. Significant judgment is required in determining our provision for income taxes. Various internal and external factors may have favorable or unfavorable effects on our future provision for income taxes, income taxes receivable, and our effective income tax rate. These factors include, but are not limited to, changes in tax laws, regulations and/or rates, results of audits by tax authorities, changing interpretations of existing tax laws or regulations, changes in estimates of prior years’ items, the impact of transactions we complete, future levels of research and development spending, changes in the valuation of our deferred tax assets and liabilities, transfer pricing adjustments, changes in the overall mix of income among the different jurisdictions in which we operate, and changes in overall levels of income before taxes. Furthermore, new accounting pronouncements or new interpretations of existing accounting pronouncements, and/or any internal restructuring initiatives we may implement from time to time to streamline our operations, can have a material impact on our effective income tax rate. Tax examinations are often complex as tax authorities may disagree with the treatment of items reported by us and our transfer pricing methodology based upon our limited risk distributor model, the result of which could have a material adverse effect on our financial condition and results of operations. Although we believe our estimates are reasonable, the ultimate outcome with respect to the taxes we owe may differ from the amounts recorded in our financial statements, and this difference may materially affect our financial position and financial results in the period or periods for which such determination is made. 51 Table of Content Our pricing structures for our solutions may change from time to time. In some cases, we offer our solutions at a higher price point than many of our competitors, and this may change in the future. We have changed our pricing, licensing, and subscription models in the past and expect that we will further change them from time to time in the future, including as a result of competition, global economic conditions, general reductions in our customers’ spending levels, pricing studies, AI, new delivery models or changes in how our solutions are broadly offered or consumed. Similarly, as we introduce new solutions, or as a result of the evolution of our existing solutions, we may have difficulty determining the appropriate price structure for our solutions. In addition, as new and existing competitors introduce new solutions that compete with ours, or revise their pricing structures, we may be unable to attract new customers at the same price or based on the same pricing model as we have used historically. Moreover, as we continue to target selling our solutions to larger organizations, these larger organizations may demand substantial price concessions. In addition, we may need to change pricing policies to accommodate government pricing guidelines for our contracts with Public Sector Customers. If we are unable to modify or develop pricing models and strategies that are attractive to existing and prospective customers, while enabling us to significantly grow our sales and revenue relative to our associated costs and expenses in a reasonable period of time, our business, financial condition, and results of operations may be adversely impacted. If we fail to maintain an effective system of internal controls, our ability to produce timely and accurate financial statements or comply with applicable regulations could be impaired. As a public company, we are subject to the reporting requirements of the Exchange Act, the Sarbanes-Oxley Act, and the rules and regulations of the listing standards of Nasdaq. We expect that the requirements of these rules and regulations will continue to increase our legal, accounting, and financial compliance costs, make some activities more difficult, time-consuming, and costly, and place significant strain on our personnel, systems, and resources. The Sarbanes-Oxley Act requires, among other things, that we maintain effective disclosure controls and procedures and internal control over financial reporting. We are continuing to develop and refine our disclosure controls and other procedures that are designed to ensure that information required to be disclosed by us in the reports that we will file with the SEC is recorded, processed, summarized, and reported within the time periods specified in SEC rules and forms and that information required to be disclosed in reports under the Exchange Act is accumulated and communicated to our principal executive and financial officers. We may also need to improve our internal control over financial reporting. Some members of our management team have limited or no experience managing a publicly traded company, interacting with public company investors, and complying with the increasingly complex laws pertaining to public companies, and we have limited accounting and financial reporting personnel and other resources with which to address our internal controls and related procedures, including complying with the auditor attestation requirements of Section 404 of the Sarbanes-Oxley required to be included in our annual reports filed with the SEC. We may need to hire and successfully integrate additional accounting and financial staff with appropriate company experience and technical accounting knowledge. In order to maintain and improve the effectiveness of our disclosure controls and procedures and internal control over financial reporting, we have expended, and anticipate that we will continue to expend, significant resources, including accounting-related costs and significant management oversight. 52 Table of Content Our current controls and any new controls that we develop may become inadequate because of changes in conditions in our business. Further, we may identify in the future deficiencies in our controls. Any failure to develop or maintain effective controls or any difficulties encountered in their implementation or improvement could harm our results of operations or cause us to fail to meet our reporting obligations and may result in a restatement of our financial statements for prior periods. Any failure to implement and maintain effective internal control over financial reporting also could adversely affect the results of periodic management evaluations and annual independent registered public accounting firm attestation reports. Ineffective disclosure controls and procedures and internal control over financial reporting could also cause investors to lose confidence in our reported financial and other information, which could have a negative effect on the trading price of our securities. In addition, if we are unable to continue to meet these requirements, we may not be able to remain listed on Nasdaq. Any failure to maintain effective disclosure controls and internal control over financial reporting could have a material and adverse effect on our business and results of operations and could cause a decline in the price of our securities. If our estimates or judgments relating to our critical accounting policies prove to be incorrect, our results of operations could be adversely affected. The preparation of financial statements in conformity with GAAP requires management to make estimates and assumptions that affect the amounts reported in our consolidated financial statements and accompanying notes appearing elsewhere in this Annual Report. We base our estimates on historical experience and on various other assumptions that we believe to be reasonable under the circumstances, as discussed in “Part II, Item 5. Operating and Financial Review and Prospects—E. Critical Accounting Estimates.” The results of these estimates form the basis for making judgments about the carrying values of assets, liabilities, and equity, and the amount of revenue and expenses. Significant estimates and judgments involve: revenue recognition; contract acquisition costs; valuation of our ordinary shares, Price Adjustment Shares and share-based compensation; fair values of assets acquired and liabilities assumed in connection with the Merger; and income taxes. Our results of operations may be adversely affected if our assumptions change or if actual circumstances differ from those in our assumptions, which could cause our results of operations to fall below the expectations of securities analysts and investors, resulting in a decline in the market price of our securities.
A. HISTORY AND DEVELOPMENT OF THE COMPANY We were incorporated on April 13, 1999 as a private limited liability company under the laws of the State of Israel. We are registered under the Israeli Companies Law as Cellebrite DI Ltd., and our registration number with the Israeli Re…
A. HISTORY AND DEVELOPMENT OF THE COMPANY We were incorporated on April 13, 1999 as a private limited liability company under the laws of the State of Israel. We are registered under the Israeli Companies Law as Cellebrite DI Ltd., and our registration number with the Israeli Registrar of Companies is 51-276657-7. Our registered office is currently located at 94 Shlomo Shmelzer Road, Petah Tikva 4970602, Israel, which also currently serves as our principal executive offices, and our telephone number is +972-(73) 394-8000. On April 8, 2021, we entered into a Business Combination Agreement and Plan of Merger (the “Merger Agreement”) with TWC Tech Holdings II Corp. a publicly listed special purpose acquisition company in the USA (“TWC”, or the “Sponsor”) and Cupcake Merger Sub, Inc., a new wholly-owned subsidiary of Cellebrite (“Merger Sub”). On August 30, 2021, the Merger was consummated and Merger Sub merged with and into TWC, the separate corporate existence of Merger Sub ceased and TWC became the surviving corporation and a wholly-owned subsidiary of Cellebrite (the “Closing”). The security holders of TWC became security holders of Cellebrite and Cellebrite became a publicly traded company with its securities listed on Nasdaq (the transactions consummated are referred to herein as the “Merger). 53 Table of Content On August 15, 2024, we announced a redemption of our Warrants to purchase Ordinary Shares, following which 19,878,580 Public Warrants were exercised on a cashless basis, 4,645 Public Warrants were exercised for cash and all of the 9,666,667 outstanding Private Warrants were exercised on a cashless basis, resulting in the issuance of an aggregate of 10,109,085 Ordinary Shares. The 116,224 remaining outstanding Public Warrants were redeemed on September 16, 2024 (the “Warrant Redemption”). Our capital expenditures amounted to $13.2 million, $8.6 million and $5.2 million during the fiscal years ended December 31, 2025, 2024 and 2023. For information on our current capital expenditures, see “Part I, Item 5. Operating and Financial Review and Prospects—B. Liquidity and Capital Resources.” We are subject to certain of the informational filing requirements of the Exchange Act. Our SEC filings are available to you on the SEC’s website at www.sec.gov, which contains reports, proxy and information statements, and other information regarding issuers that file electronically with the SEC (including, in our case, our annual reports on Form 20-F, our reports of foreign private issuer on Form 6-K, any amendments to these reports, as well as certain other SEC filings). We also make available on our website, free of charge, all such SEC filings as soon as reasonably practicable after they are electronically filed with or furnished to the SEC. Our website address is https://www.cellebrite.com. The references to the SEC’s and our website are inactive textual references only, and information contained therein or connected thereto is not incorporated into this Annual Report. Since we are a “foreign private issuer,” we and our officers, directors and principal shareholders are exempt from certain rules and regulations under the Exchange Act. For more information, see “Part I, Item 10. Additional Information—H. Documents on Display.” B. BUSINESS OVERVIEW Overview Overview & Mission Our mission is to provide AI-powered digital investigative and intelligence software solutions that help protect nations, communities and businesses. Cellebrite technology allows customers to accelerate more than 1.5 million legally sanctioned investigations annually, enhance sovereign security, elevate operational efficacy and efficiency, and enable advanced mobile research and application security. By using Cellebrite’s solutions, public and private sector customers around the world are transforming their investigative workflows, making forensically sound digital data more accessible and actionable, and elevating the efficiency and effectiveness of mobile research and application security. For nearly 20 years, Cellebrite has leveraged its extensive expertise in mobile phones, including its deep understanding in hardware, firmware and operating systems, and in other digital sources to develop and market an increasingly integrated platform of software solutions used to access, collect, review, extract, decode, decrypt, analyze, share and manage digital evidence across the investigative lifecycle. As digital evidence has become integral to nearly every criminal investigation, our solutions are relied upon by our customers to advance the investigative lifecycle. With most major crimes now having a digital component, we continue to see healthy demand for our solutions, which are used to advance a wide range of investigations spanning child exploitation, homicide, anti-terror, border control, sexual crimes, organized crime, human trafficking, financial crimes including those involving cryptocurrency, corporate security, and intellectual property theft. Our solutions are designed to help law enforcement agencies protect their communities more effectively and efficiently by advancing investigations in order to successfully prosecute criminals, and exonerate the innocent. Defense and intelligence agencies use our solutions to enhance border security, advance counter terrorism and intelligence operations, conduct sensitive site exploitation, increase military readiness, and support cyber operations. Our software also enables enterprises and service 54 Table of Content providers to collect and review data in support of corporate investigations, eDiscovery and incidence response events, as well as to more efficiently and effectively design and validate next-generation mobile applications. Industry Background Public safety is among the top priorities for national, regional and local governments around the world. Unfortunately, a pronounced public safety gap has occurred over the past decade due to a combination of factors including high crime rates, increasingly sophisticated criminals, the proliferation of digital sources, strained law enforcement manpower and limited financial resources, and heightened public scrutiny on police operations. We believe that the gap in public safety requires an ongoing investment in advanced technology that addresses increasing data volumes and complexity, and digitally transforms previously manual, time-consuming and inefficient elements of our customers’ workflows while elevating public confidence in how law enforcement and other public safety agencies conduct their investigations. According to multiple studies and reports, including those from Europol and International Business Machines Corporation, more than 90% of all reported crime has a digital element. Given this dynamic, digital data is changing the way criminal cases are investigated, prosecuted and defended. By using the right tools and solutions to collect, review, analyze and manage data from a wide range of digital sources, law enforcement and other agencies can better identify relevant and impactful information contained within vast volumes of complex data at scale. As a result, they are better positioned to accelerate investigations and close more cases faster while reducing device backlog and increasing efficiencies. Technology is also transforming other key elements within the digital investigative lifecycle. The use of AI-driven and other powerful tools, systems and solutions enables law enforcement agencies to reduce or eliminate previously manual, time-consuming tasks. By using powerful analytic engines that are enhanced by AI, machine learning models and other sophisticated technological capabilities, investigators are better equipped to generate insights into vast volumes of disparate, unstructured and structured data, which supports their efforts to expedite cases and accelerate justice. Scalable, secure management platforms can assist law enforcement agencies to ensure compliance with agency protocols and various regulatory requirements, thereby strengthening the chain of custody while making it easier and faster to share evidence-related information among authorized parties in a verifiable, defensible, secure and scalable manner. As a result of these benefits, we believe that demand for our solutions will remain strong for the foreseeable future while also informing the ongoing enhancement and expansion of our solutions. In addition, to efficiently and effectively investigate and prosecute criminal actors and eliminate threats to national security, law enforcement and defense and intelligence agencies need powerful technology to help them gain insight into the security and architectural complexity of smartphones, laptops, tablets, wearable devices and a range of other connected devices and systems. In the private sector, access to and insights into digital data is critical to advancing eDiscovery, corporate investigations and incidence response. Intellectual property (IP) protection and data theft by existing or departing employee remains a top use case given the potential damage that IP theft can cause. For businesses in highly regulated industries such as financial services, insurance, banking, healthcare, pharmaceuticals, transportation and energy, access to data and sound records management are fundamental to eDiscovery and compliance. Other important private sector use cases for digital forensics software involve investigating claims of harassment, contractual disputes, discrimination and other workplace issues, lawsuits from regulators, customers or partners due to data breaches as well as retrieving inaccessible, lost, corrupted or damaged data. Given the high cost associated with security breaches, enterprises are increasingly recognizing the value of investing in incidence response solutions that can quickly gather data to assess the impact of the attack, accelerate response time and analyze information from multiple sources to develop plans to strengthen their cyber defenses against future attacks. Furthermore, enterprises face significant challenges in developing and testing mobile 55 Table of Content applications, particularly as it relates to ensuring security across the widest range of phones and operating systems Cellebrite’s Digital Investigation Platform: Key Products & Services Digital Forensics Software •Cellebrite’s Inseyets suite of digital forensics software is used by examiners and other law enforcement professionals within the Digital Forensic Units of law enforcement agencies and by trained professionals across a wide range of federal or national agencies, to collect and review digital evidence from the broadest range of digital sources when conducting legally sanctioned investigations. More specifically, as a result of a search warrant or owner consent, our digital forensics solutions are designed to help our users lawfully access and extract digital data, including encrypted, deleted or hidden data, from the widest range of mobile phones, including smartphones, feature phones and basic phones, computers and cloud-based applications. We also provide a decoding solution that converts the raw binary data extracted from mobile phones, tablets, computers, cloud-based applications, automobiles, open source information, GPS devices, memory sticks, drones, and call detail records (“CDRs”) as well as from other digital sources like the web into human readable format that can be used by relevant stakeholders. Our digital forensics software is designed to help law enforcement agencies of all sizes complete device examinations faster, thereby supporting their efforts to expedite investigations and reduce device backlog. Cellebrite’s AI-powered capabilities enable examiners to quickly identify and validate potentially valuable digital evidence. Customers can also subscribe to our specialized unlock module that provides lawful access to locked devices, enabling the extraction of critical information from a broad range of the newest and most advanced smartphones. Through technical alliances with specialist technology vendors, we also make it possible to analyze blockchain transactions together with related data from an extensive list of sources to help investigators identify and categorize wallets and transactions. In the private sector, Cellebrite’s enterprise and service provider customers use our products to enable legal, compliance and cybersecurity corporate staff to collect digital data from mobile phones, computers and business cloud-based applications. Cellebrite’s digital forensic software offerings for the private sector are consent-based, capturing the necessary data to advance eDiscovery and corporate investigations, which in turn, enables the customer to build a comprehensive digital picture, recover critical information, better understand cybersecurity intrusions — all while protecting employees’ privacy. Certain Cellebrite offerings are available as SaaS or on premise solution to address the customer’s particular needs. Digital Investigations and Analytics •Guardian Forensics: Cellebrite’s evidence management solution, Guardian Forensics, enables customers to manage their digital forensics workflows, and to store, share and review digital evidence. This offering helps customers fortify the chain of custody processes for digital evidence through the creation of a verifiable, defensible audit trail, adhere to agency processes, automate key workflows, accelerate time to evidence and reduce time-consuming and error-prone processes when reviewing digital evidence reports. 56 Table of Content •Guardian Collaborate: Cellebrite’s digital evidence sharing tool, Guardian Collaborate, provides enterprises with the capability to securely share and review mobile data instantly, without the need for complex forensic tools or IT-heavy deployments. Designed for HR, Legal, Compliance, and Internal Investigations teams, this solution streamlines workflows by providing a simple, browser-based interface for evidence review, collaboration, and reporting. •Guardian Investigate: Planned for introduction in early 2026, Cellebrite’s case management and AI-powered analytics solution, Guardian Investigate, provides investigators, detectives, analysts and prosecutors with a SaaS data repository for the records, information and data relevant to an investigation as well as tools for collaboration and task management, and AI-powered analytics for mobile phones and a range of other diverse data sources such as call detail records, open source intelligence, warrant returns, closed circuit television videos. This offering is designed to empower agencies to accelerate case resolution, improve collaboration, and achieve greater investigative impact through a single, cohesive ecosystem. •Cellebrite Pathfinder: Cellebrite’s AI-powered analytical software solution, Pathfinder, is used to examine volumes of digital data collected from multiple smartphone devices. This solutions helps investigators, analysts, prosecutors and other relevant personnel accelerate legally sanctioned investigations by surfacing leads, highlighting patterns and identifying important connections. Leveraging AI and machine learning, Pathfinder helps automate data analysis and visualization, which, in turn, reduces the time spent manually reviewing digital evidence and enables actionable insights into a wide range of crime types. We also provide, in collaboration with our partners, CryptoCurrency Investigative Solutions for analyzing blockchain transactions together with related data from an extensive list of sources to help investigators identify and categorize wallets and transactions. Prevention & Intelligence Corellium, which Cellebrite acquired in December 2025, provides virtualization software for devices that rely on power-efficient Arm processors (“Arm-based Virtualization Software”). Corellium’s software empowers developers and security experts to research, work, and test seamlessly on an ever-expanding range of devices, from mobile smartphones, tablets and laptops to physical devices embedded with software and connectivity (IoT, Internet of Things) and industrialized systems. The acquisition brings two primary offerings that form the foundation of Cellebrite’s prevention and intelligence offerings: •Corellium Falcon: This offering enables researchers within government organizations include defense and intelligence agencies, as well as specialized technology vendors who support these 57 Table of Content organizations to efficiently and effectively conduct mobile vulnerability research, exploit introspection, and malware analysis not possible on physical iOS and Android devices. •Corellium Viper: This offering provides a library of virtual iOS and Android devices that enable rapid, cost-efficient mobile application penetration testing capabilities. Cellebrite’s Professional Services •Training and Certification Services: Cellebrite’s Training and Certification Services are focused on maintaining the highest standards for professional development in digital forensics. Backed by decades of field experience, our certified instructors deliver hands-on, solution-focused education that enables examiners, investigators, and other agency personnel to achieve operational excellence. In 2025, Cellebrite delivered more than 400 classes across 15 courses spanning in-person, virtual, and self-paced online formats, serving thousands of professionals worldwide. Each year, approximately 11,000 students earn Cellebrite certifications — reinforcing our role as a trusted partner in strengthening investigative capabilities and advancing justice through expertise. •Cellebrite Advanced Services: Cellebrite’s expert team serves as an extension to customer digital forensics lab teams, providing advanced services in Cellebrite’s Global Lab facilities to help organizations access and extract digital evidence in support of ongoing active legally sanctioned investigations. Cellebrite Advanced Services helps its customers reduce device backlog and address evolving technological workloads. Customers Cellebrite’s base of approximately 7,000 customers include approximately 5,300 federal, state and local agencies as well as approximately 1,700 corporations and service providers. In 2025, Cellebrite’s Public Sector Customers accounted for more than 90% of total revenue. Initial deployments by national, regional and local law enforcement agencies primarily involve our digital forensics software. Over time, we have successfully increased our business with many of these customers as they expanded their operations and deployed additional digital forensic solutions from us with specialized capabilities that have helped them further modernize their investigative workflows and make digital evidence more accessible, intelligent and actionable. We also cross-sell and upsell our investigative solutions into the Investigative & Intelligence Units of our customers. In the private sector, we target primarily larger enterprises and service providers which are contracted by corporations to oversee eDiscovery and corporate investigatory activities. Our ability to expand existing customer relationships is partially reflected in our 116% recurring revenue dollar-based net retention rate (NRR) as of December 31, 2025. While we have an extensive global customer base that serves as the foundation for much of our growth, we continue to win business with new public and private sector customers. In 2025, these new logo wins contributed less than two percentage points to our annual recurring revenue growth. Within a law enforcement agency, we primarily sell to Investigative & Intelligence Units with a historical focus on their Digital Forensic Units. Most mid-sized and large-sized law enforcement agencies have dedicated digital forensics units in which examiners and other professionals use specialized tools and solutions in dedicated laboratory environments that enable them to identify, acquire, process, analyze, and report on data stored electronically from a wide range of digital sources. Smaller agencies may operate digital forensic units with limited resources or cross-train investigators and other staff to use digital forensics software and other related tools in support of their investigative efforts. In addition to use within digital forensics laboratories, our solutions are used by customers in the field (outside of a traditional laboratory environment) consistent with specific use-case requirements or the customers’ mode of operations. The digital evidence collected by the professionals within the digital forensics units can be shared with investigators, prosecutors and others involved in the case. Investigative units using our 58 Table of Content solutions are typically responsible for the investigation of serious crimes including child exploitation, homicide, anti-terror, border control, sexual crimes, organized crime, human trafficking, financial crimes including those involving cryptocurrency, corporate security, and intellectual property theft. Investigative units within larger law enforcement agencies sometimes establish and manage multiple divisions or sub-units comprising teams of detectives, investigators, analysts or other specialized professionals who focus on specific crime types such as homicide, gangs, sex crimes, crimes against children, narcotics and many others. No organization accounted for more than 5% of our total 2025 revenue. Our top 25 customers accounted for 25% of total 2025 revenue, which compares with our top 25 customers accounting for 25% of total 2024 revenue. Our customer base is geographically diverse. For a breakdown of our revenue by geography, see Note 17 to our consolidated financial statements in “Part III, Item 18. Financial Information.” Historically, we generate the majority of our revenue in the second half of our fiscal year with 54%, 54% and 54% of total annual revenue occurring in the second half of 2025, 2024 and 2023, respectively. This trend primarily reflects the timing of subscription agreements for our on-premise software solutions with U.S. federal customers to align with the end of their fiscal year in September, and with many other customers around the world to align with the end of their fiscal year in December. Over the past several years, we have successfully transitioned the vast majority of our customers from perpetual software licenses to subscription licenses. Total license subscription revenue represented 90%, 88% and 86% of our total annual revenue for the years ending December 31, 2025, 2024 and 2023, respectively. Growth Strategy Our growth is underpinned by an ongoing commitment to fund innovation and execute on our go-to-market initiatives intended to further expand the scope of existing customer relationships across our global customer base and win business with new customers. Our recent growth with existing Public Sector Customers has been primarily driven by expanding usage of current products and helping customers adopt new software solutions. In 2026, we expect to further expand our business through the following strategies: •New logos, upgrades, and annual price increases: We continue to broaden our customer base by winning new customers. In addition, we continue to evolve the mix of offerings used by customers and escalate prices in line with market conditions. •Digital Forensics growth: We continue to drive growth by converting customers using our legacy digital forensics solution to Inseyets, increasing the adoption of Inseyets with current and prospective customers, and by extending our reach into new user groups within our installed customer base by selling advanced unlock solutions and automation offerings. •Greater adoption of Cellebrite’s Digital Investigation and Analytics offerings: We seek to further expand the number of customers who use our Guardian Forensics solution. In addition to ongoing go-to-market initiatives to support adding more customers within U.S. state and local governments, Latin America and United Kingdom, we plan to make our Guardian Forensics solution available to U.S. Federal agencies by achieving FedRAMP authority to operate, and by extending into other select international markets and by selling a private sector version of Guardian Forensics to our enterprise customers. We will continue to focus on increasing adoption of our digital investigation and analytics solutions among our existing base of law enforcement, defense and intelligence agency customers around the globe. We also expect that our Guardian Investigate solution will be generally available in early 2026. •Leverage our global go-to-market capabilities to sell Corellium solutions: We will focus on capitalizing on opportunities to sell Corellium’s solutions into our global customer base across our defense, intelligence and enterprise verticals. 59 Table of Content •Improved retention: We continue to invest across our go-to-market organization in people, processes and systems, as well as evolve our pricing and packaging, to support improved retention rates by minimizing churn. Our business has historically generated strong cash flow from operations and has been minimally capital intensive. As of December 31, 2025, we reported cash and cash equivalents, cash deposits, short-term marketable securities and long-term marketable securities totaling $535.0 million with no outstanding debt. With a strong financial foundation, our growth strategy also includes disciplined pursuit and evaluation of acquisition candidates that can help us accelerate innovation and speed time to market with enhanced and new offerings, capabilities and features that can deepen existing customer relationships, increase our customer base, expand our total addressable market, accelerate revenue growth, or gain further operational scale. Research and Development Our ongoing investment in research and development is focused on enhancing our existing offerings with new features, functionality and capabilities as well as developing new products aiming to address evolving customer needs. Our extensive domain expertise and understanding of our customers’ workflows and related requirements is critical to understanding their most painful challenges. We invest considerably in mobile research, utilizing teams of experts who apply specialized skills and domain knowledge to advance the access, extraction and decoding capabilities of our digital forensic software in order to keep pace with ever-changing smartphone hardware, operating systems and related applications. We also augment our internal mobile research teams through partnerships with third-party specialists who help us further expand our library of mobile phone exploits. In addition, we continue to expand our investment in artificial intelligence, with a particular focus on advancing our analytics capabilities through the integration of next-generation AI technologies, including Generative AI and agentic AI. These initiatives strengthen our ability to deliver deeper insights, greater automation, and improved decision support across our solutions. We also continue to cloud-enable more solutions and capabilities that were previously only made available through on-premise deployments and add new features and functionality to our SaaS solutions. We also modify and enhance certain digital forensic solutions for our Public Sector Customers and develop new capabilities that address the specific needs of our enterprise customers and service providers, including capabilities aimed at helping them identify relevant data faster. Technology Infrastructure Historically, our software solutions were deployed on premise by our customers. In recent years, our customers have begun to utilize cloud-delivered solutions. We have responded by evolving our technology infrastructure and software development. We work closely with Amazon Web Services (AWS) to develop and scale our Cellebrite Cloud Platform, which we use to deliver our cloud-delivered solutions across the digital investigation end to end flow. As we drive greater adoption of our cloud-delivered solutions, we plan to continue making investments to further scale our Cellebrite Cloud Platform infrastructure, aiming to achieve compliance with various technical program requirements, standards and certifications for deployment of our cloud-delivered solutions at scale by federal and state government customers in the different regions we sell to. We believe that these investments will enable our customers to leverage their use of our cloud-delivered offerings, support faster and more cost-effective procurement processes, eliminate duplicative assessment efforts and ensure consistent application of information security standards. In addition, we will continue to thoughtfully evolve our go-to-market plans to deliver our cloud-based solutions in ways that align with the customers and geographies best suited for near-term adoption. 60 Table of Content Go-to-Market: Sales, Marketing, Customer Success & Technical Customer Support Sales Our sales and marketing activities reflect the size of the customer opportunity. We target public and private sector Customers either directly through our sales force or indirectly service providers and resellers. The majority of our subscription agreements with public and private sector customers are one year in length, which lends itself to a high-touch sales approach in order to produce strong retention rates and to advance new sales activities. Over time, we have seen more public sector agency budgets being diverted to digitally transform the investigative workflow and to help close the growing public safety gap. More recently, as a result of the evolving geopolitical landscape and regional conflicts around the world, we have seen increased funding to defense and intelligence agencies to support border control, counter intelligence and counter terrorism, and overall military readiness. We utilize a combination of direct sales and indirect channels to reach Public Sector Customers. Account executives and sales managers directly manage relationships with our largest customers while dedicated inside sales teams or resellers typically work with smaller customers. We sell to decision makers in public safety, which include the chiefs of investigations or the head of investigations and intelligence, or the heads of digital forensics labs. Our sales professionals work with current and prospective customers to understand and address the challenges they face, enabling them to identify opportunities to expand sales volumes, introduce key offerings within our full suite of solutions, and cultivate relationships with key decision makers in new buying centers within large agencies. In smaller accounts, we typically sell to police chiefs, senior law enforcement professionals or those charged with overseeing the agency’s digital forensics labs. We augment our direct sales staff with pre-sales engineering resources to showcase our offering, support technical configurations and deploy our solutions. We utilize an inside sales organization to reach out to new Public Sector Customers. In the private sector, we mainly sell to legal, compliance, internal investigation groups or eDiscovery groups within enterprises, and to service providers. Our account representatives in the private sector primarily focus on new customer acquisition and expanding our enterprise solution offerings within existing and new accounts. We often utilize resellers for government agency procurement to account for our internal business and operational needs, where direct sales opportunities do not exist or where the government requires local vendors due to local requirements. In the private sector, our direct sales force in the EMEA, LATAM and Asia Pacific regions is augmented by reseller relationships. We conduct a low volume of its business via e-commerce, and our e-commerce system is available only to customers who have a valid license to use Cellebrite’s solutions. For more information regarding our e-commerce system, see – “Part I, Item 3. Key Information —D. Risk Factors — Risks Related to Cellebrite’s Business and Industry — We conduct a fairly low volume of our business via e-commerce, which may result in the purchase process being more difficult for customers compared with other businesses.” 61 Table of Content Marketing To support the expansion of existing customer relationships, our marketing campaigns highlight the value we bring to them currently while introducing the value and advantages they can derive from increasing organizational adoption of existing solutions or using additional solutions in our portfolio. We develop and implement marketing programs to educate customers and increase awareness about how they can maximize existing Cellebrite solutions utilizing relevant channels such as our online customer community, in-person, virtual and on-demand customer workshops, webinars, and other content hosted on our website such as videos, blogs, infographics and technical white papers. We also provide relevant thought leadership content that highlights feedback, best practices, emerging trends and customer success stories around “what’s now and what’s next” in digital forensics, evidence management and investigative analytics that could be used to transform their investigative workflows. In addition, we participate in and sponsor relevant industry events and trade shows, and use account-based marketing to build awareness, create demand and drive user adoption to support account growth. To attract and engage new customers, Cellebrite’s branding and public relations efforts uses a variety of channels to communicate, such as press releases, industry events, social media, content marketing, customer success stories and community engagement initiatives. Typically, we utilize a layered approach with each channel and the corresponding messaging that build on and complement one another, resulting in a demand offer that is meant to be compelling and relevant to their needs. We also measure the impact and performance of these efforts and make adjustments accordingly across channels, content, messages and offerings. In addition to participation in industry events, we also hold an annual user conference, the Case to Closure (C2C) Summit, which enables us to fortify existing customer relationships, showcase our solutions and provide high-quality educational sessions. We augment this annual conference with smaller-scale, regional events. Customer Success & Technical Customer Support We provide our customers with post-sale support to help customers maximize the utility of our offerings, address time-sensitive questions about the features and functionality of our solutions, and respond to technical issues that may arise. Our customer success teams spend time on site with customers, supporting installations, and augmenting our training programs to help customers quickly acclimate to our offerings. Our technical customer support teams operate from multiple office locations around the world, providing responsive, native language assistance by phone and email during business hours in certain countries and on a 24-hour basis in other countries. We complement and augment our support teams with a range of online resources including those available through the MyCellebrite Learning Hub and via our user community called “The 101”. Competition We deliver a broad set of capabilities across the digital investigative lifecycle to support our expansive, global customer base. We typically compete with specialized vendors who focus on addressing certain investigation workflows. Some competitors have a specialty in digital forensics software, while others primarily offer analytics tools. Nevertheless, consolidation in the industry in recent years has resulted in certain competitors providing a broader range of solutions. There are a number of companies serving the public sector who have greater name recognition and substantially greater financial, management, marketing, service, support, technical, distributions and other resources than we do. While we may not compete directly against many of these companies, spending on their products and services may be prioritized over spending on our offerings. Additionally, certain competitors may be able to leverage their technical expertise or sales resources to respond more effectively than we can to changing or emerging technologies, standards and regulations or customer requirements. 62 Table of Content Digital Forensics: Our digital forensics software offerings primarily compete with Magnet Forensics Inc. (which was merged with GrayShift in 2023), Microsystemation AB, Oxygen Forensics, Inc., and Exterro Inc. Within the Digital Forensics Units of larger customers, a multi-vendor environment is common in part because a customer may desire to verify findings from its primary solution on a secondary solution, or because certain solutions are optimized for certain device types or applications. We believe that our offerings are differentiated by: •the breadth and depth of our mobile phone coverage as well as broad support for over 31,000 physical and virtual device profiles across mobile, laptop, computers, memory containers, applications, CDRs, etc.; •advanced capabilities for lawful access and complete extraction for the most advanced smartphones with extensive, unmatched Android coverage; •best-in-class decoding of digital data across the widest range of digital sources and thousands of applications, regardless of the digital forensics software used for extraction; and •pricing that is optimized to address a wide range of customer technical requirements and budgets. In the Private Sector, our digital forensic software solutions compete with vertical software providers such as Exterro Inc., Magnet Forensics Inc., Nuix Limited, and OpenText Corporation. Private Sector service providers are typically return-on-investment driven and will decide to acquire our solutions when there is a financial justification for the investment. We believe that our digital forensic software solutions for the private sector are differentiated by: •The ability to offer an integrated suite of solutions that support both remote and on-premise data collection for mobile, computer and business applications; •Deployment flexibility with SaaS and traditional on-premise offerings; •Targeted extraction to selectively collect specific information to help save time, money and protect user privacy; •Integration with specialized, third-party processing and analytics systems typically used in corporate investigations and eDiscovery activities; and •Packaging and pricing to optimize value for service providers. Digital Investigations and Analytics: Our SaaS-based evidence management solution, Guardian Forensics, addresses a growing trend to manage digital evidence with a cloud-based delivery model, which enables investigators, prosecutors, defense attorneys and other authorized personnel to review and analyze this information. Most customers have yet to adopt workflow and evidence management solutions to support digital evidence workflows and often manage digital evidence on external storage. However, we face competition from vendors including NICE Ltd., AXON Inc., Magnet Forensics Inc., and Microsystemation AB. We believe our evidence management solution is differentiated by: •Share and review functionality for reports and evidence benefiting from our best-in-class decoding capabilities as well as AI-based analytics; •Streamlined workflows to support the management of evidence within the Digital Forensic Unit; •Monitoring and audit logs that are critical to establishing and validating the chain of custody; •User access controls and permission capabilities; •Security and scalability, which includes meeting the technical standards used in certain customer segments or in certain geographies; and •Consumption-based packaging and pricing model so that customers of any size can benefit from our Guardian Forensics solution. 63 Table of Content Within Investigative Units, our AI-powered, multi-phone analytical software solution, Pathfinder, competes against traditional business information and visualization platforms as well as specialized analytics designed for law enforcement from vendors such as N. Harris Computer (which acquired the i2 intelligence analysis product portfolio from IBM in 2022), Nuix Limited, Pen-Link, Ltd. (which also acquired Cobwebs Technologies Ltd. in 2023), Griffeye Technologies AB (acquired by Magnet Forensics Inc. in 2023) and Siren (Sindice Ltd.). We believe our AI-powered, multi-phone analytics solution is differentiated by the ability to: •Analyze vast volumes of structured and unstructured mobile data from multiple phones as well as data from other digital sources in order to surface leads and identify connections among suspects, witnesses and victims; •Apply AI and machine learning models to perform image categorization, data aggregation, audio-to-text analysis, object character recognition and facial similarities; •Support collaboration across teams and agency departments; and •Generate timely, comprehensive reports. In addition, our case management and AI-powered analytics solution, Guardian Investigate product, competes against analytics for specific data sources and investigative workflow offerings from vendors such as Peregrine Technologies, Inc., Nuix Limited, Pen-Link, Ltd., LEADSONLINE, LLC, Altia Solutions Limited, Guardify, Inc., Palantir Technologies Inc., Tranquility AI Inc., Unisys Corporation and others. We believe our Investigate solution will be differentiated by the ability to: •Ingest and analyze data from a single or multiple mobile phones; •Deploy generative AI to analyze evidentiary artifacts from an increasing range of data sources including call detail records, closed circuit television video, witness statements and open source intelligence; •Visualize relationships and connections by correlating different data sets such as mobile phone data and call detail records; •Leverage agentic AI to support crime-type specific investigative workflows; •Advance investigations through secure storage, sharing and collaboration including assigning tasks, tracking progress and building timelines; and •Fortify the chain of custody. Prevention and Intelligence: The acquisition of Corellium in December 2025 has enabled us to provide highly differentiated, Arm-based Virtualization Software offerings that empower developers and security experts to research, work, and test seamlessly on an ever-expanding range of devices, from mobile smartphones to IoT and industrialized systems. Corellium’s virtualization solutions compete against a range of offerings including Android emulators, mobile security and mobile application testing tools; enterprise information management software; electronic design automation solutions; and hybrid cloud testing offerings. While these alternatives can address certain customer requirements, we believe Corellium’s Arm-based Virtualization Software provides improved functionality, greater convenience, efficiency and scalability, lower overall cost and time savings. More specifically, we believe Corellium’s offerings are differentiated by: •Arm-on-arm virtualization through the Corellium Hypervisor for Arm (CHARM) technology that allows developers and researchers to run virtualized iOS and Android mobile devices, as well as custom Arm-based IoT devices, directly on Arm servers; •Multi-platform spanning Android, Apple iOS and IoT operating systems; •Flexibility in deployment spanning on-premises and cloud; •Mission-critical tools to support the mobile vulnerability research, exploit introspection, and malware analysis requirements of defense and intelligence agencies; 64 Table of Content •Self-service, automated mobile application security testing capabilities; •Root access and kernel coverage for the latest generation of mobile devices; and •Cloud native research and development tools. Subscription Terms The subscription to use our products is granted to customers on a limited, non-transferable, non-sublicensable, territory and subscription basis. The subscription contains customary undertakings from customers and additionally requires them not to use the software in violation of applicable laws (including laws with respect to privacy and other human rights and the rights of individuals), any human rights standards and best practices including internationally recognized human rights instruments, such as the Universal Declaration of Human Rights, or in support of any illegal activity or to violate the rights of any third party. We may terminate any license, among other things, in the event of a material breach that is not cured after 30 days’ notice. In addition, we may disable the use of our software, among other things, if it is determined that our products were used in violation of the license or applicable laws. Regulations We are subject to various laws and regulations on import and export controls, sanctions, privacy, and data protection. In addition to the regulations outlined below, our operations also are subject to various laws and regulations governing employment matters, and the occupational health and safety of our employees and wage regulations. Export Controls The export of some of our products and solutions is subject to Israeli export control laws which are administered by the Israeli Defense Export Controls Agency (“DECA”) within the Ministry of Defense. We currently operate under an export license issued pursuant to the Israeli encryption control regime. Israeli export control laws and regulations as well as the licenses granted to us by DECA prohibit us from exporting some of our products to customers in certain countries and require us to obtain the consent of DECA to export some of our products to customers in certain other countries. On November 18, 2025, the Israeli Minister of Defense signed an order repealing the current encryption control regime and adopting a new regime. The new regime becomes effective on March 18, 2026. We believe that under this order our current license will remain valid until September 2027 with respect to our existing products. Under the new regime, some of our solutions will become subject to the Wassenaar Arrangement. The Wassenaar Arrangement is a multilateral export control regime with 42 participating states. Although Israel is not a party to the Wassenaar Arrangement, it has adopted the Wassenaar Arrangement List of Dual Use Goods and Technologies and the goods and technologies listed therein, which could be understood to include digital forensic technologies as well as the cryptographic capabilities in our products, are subject to Israeli export control laws and regulations. As a result, we expect that some of our products will be controlled primarily under the Israeli Defense Export Control Law, 5767-2007 administered primarily by DECA and, to a lesser extent, the Import and Export Order (Export Control over Dual Use Goods, Services and Technology), 5766-2006, administer primarily by the Ministry of the Economy, in each case, depending on the nature of the customer. This outcome will result in the imposition of new obligations on us. For example, under the Defense Export Control Law, 5767-2007, an Israeli company may not conduct “defense marketing activity” without a defense marketing license from the Israeli Ministry of Defense and, subject to certain exceptions, is subject to a licensing requirement from the Israeli Ministry of Defense for the export of any controlled defense goods, services and/or know-how. The definition of defense marketing activity is broad and includes any marketing of “defense equipment, services and/or know-how” outside of Israel or to a non-Israeli (including within Israel) regarding controlled dual-use equipment, services and/or know-how. If this provision is determined to apply to some or all of our products, we would likely need to adapt our 65 Table of Content licensing, marketing and export practices to accommodate this regulatory change. We are currently in discussions with representatives of DECA regarding the possibility of continuing our export activities consistent with our practices under our current license. Import Regulations Various other countries in which we operate regulate the import of certain decryption and cryptographic solutions and technology, including import permitting and licensing requirements, and have enacted laws that could limit our ability to distribute our solutions or could limit our customers’ ability to implement our solutions in those countries. Sanctions Our activities are subject to certain economic sanctions laws including under the laws of the State of Israel and the United States. In addition, we have adopted policies and procedures to restrict sales in certain additional countries. Data Privacy Given the global nature of our operations, we are subject to a variety of local, state, national, and international laws and directives and regulations related to privacy and data protection, data security, data storage and retention, data transfer and deletion, and technology protection. Our products are mostly used as an on-premise solution and are generally operated by our customers without our involvement. Nevertheless, our service operators occasionally have brief and limited access to customer data, including PII, when they receive calls for technical support, or when they maintain or operate the relevant solution. One instance where we may have access to personal information and investigative data is when a customer calls for technical support, they sometimes share data with our technical support teams or grant service operators access to data for the purpose of performing services, such as bug fixing, research and analysis. We have internal processes for deleting such data shortly after the completion of customer support. In addition, customers may use our investigative management solution, the Guardian, to store, share and review sensitive data, including PII, when they decide to store such data in our investigative management SaaS-based solution. In addition, as part of the provision of our Advanced Services in which we serve as an outsourced lab, we extract data that may include sensitive data and PII, from digital sources that are sent to us by our customers. In the performance of such Advanced Services, we maintain such data securely with limited access, and delete such data following confirmation that the data has been received by the customer. Virtually every jurisdiction in which we operate has established its own legal framework relating to privacy, data protection, and information security matters with which we and/or our customers must comply. Laws and regulations in these jurisdictions apply broadly to the collection, use, storage, retention, disclosure, security, transfer, and other processing of data that identifies or may be used to identify or locate an individual. Some countries and regions have passed legislation that imposes significant obligations in connection with privacy, data protection, and information security. United States The United States has federal and state laws and regulations regarding privacy and information security, including consumer protection laws (e.g., Section 5 of the Federal Trade Commission Act), data breach notification laws, and personal data privacy laws. States continue to revise and pass new privacy-related legislation. For example, the California Consumer Privacy Act (CCPA) and follow-on legislation in the California Privacy Rights Act (CPRA), provide for civil penalties for violations, as well as a private right of action for data breaches that may increase data breach litigation. The CPRA also created a new state agency that is vested with authority to implement and enforce the CCPA and the CRPA. Similar laws passed in numerous other U.S. states that are currently in effect or will become effective in the near future. Additional U.S. states are considering, similar data privacy laws. We cannot fully predict the impact of these state laws on our business or operations, but they may require us to modify our data 66 Table of Content processing practices and policies and to incur substantial costs and expenses in an effort to comply. In addition to the growing number of state-level privacy laws, the U.S. Congress has been actively considering a federal privacy law for some time which, if passed, would likely create a comprehensive national framework for data protection and privacy. This law could supersede many state privacy laws and establish uniform privacy protections across the country, addressing issues such as data security, artificial intelligence governance and consumer rights. The final form, timeline, and effective date of a potential U.S. federal privacy law is uncertain at this time. Europe and UK We are required to comply with the GDPR and, following the exit of the UK from the EU, the UK equivalent. For the purposes of the GDPR and the UK equivalent, we are not considered to be a controller regarding our customers' PII processed as part of the services provided to them and serve as a processor in a limited number of circumstances. Implementation of the GDPR and the UK equivalent exposes us to two parallel data protection regimes, each of which impose several stringent requirements for controllers and processors of personal data and could make it more difficult to and/or more costly for us to collect, store, use, transmit and process personal and sensitive data. Among other requirements, the GDPR regulates transfers of personal data subject to the GDPR to third countries that have not been found to provide adequate protection to such personal data, including the United States, and the efficacy and longevity of current transfer mechanisms between the EEA and the United States remains uncertain. A decision from the CJEU states that reliance solely on the Standard Contractual Clauses - a standard form of contract approved by the European Commission as an adequate personal data transfer mechanism - may not necessarily be sufficient in all circumstances and that transfers must be assessed on a case-by-case basis. In 2022, the EU and U.S. established the EU-US DPF, a GDPR transfer mechanism to U.S. entities self-certified under the DPF. The DPF also introduced a new redress mechanism for EU citizens which addresses a key concern in the previous CJEU judgments. Similar mechanisms are also in place under UK law following the UK’s exit from the EU in 2021. Non-compliance with the GDPR and the UK equivalent legislation may result in administrative fines or monetary penalties of up to 4% of worldwide annual revenue in the preceding financial year or €20 million (or GBP 17.5 million under the UK legislation), whichever is higher for the most serious infringements, and could result in proceedings against us by governmental entities or other related parties and may otherwise adversely impact our business, financial condition, and results of operations. Israel The Israeli Privacy Protection Law, 1981 ("PPL"), along with its regulations such as the Israeli Privacy Protection Regulations (Data Security) 2017 ("Security Regulations"), mandates strict requirements for processing, transferring and securing personal data. A significant amendment to the PPL, known as Amendment 13, was approved by the Israeli Parliament in August 2024 and became effective on August 14, 2025. This amendment notably enhances the investigative powers of the Privacy Protection Authority and increases the potential monetary sanctions for violations, which could reach millions of NIS in certain cases. Compliance with Amendment 13 may necessitate substantial changes to our data processing practices and could involve significant costs. Non-compliance with the PPL may lead to enforcement actions, litigation, including class actions, and substantial fines and penalties. AI As we continue to innovate and improve our offerings by leveraging AI, jurisdictions are turning increasing attention to the regulation and governance of the use of AI and machine learning technologies. As these legal requirements evolve, we may face additional scrutiny and regulation, and bear increased compliance costs and other exposures, associated with the regulation of our use of such technologies. In addition, we may become subject to new or heightened legal, ethical or other challenges arising out of the perceived or actual impact of AI on human rights, intellectual property, privacy and employment, among other issues, and we may experience brand or reputational harm, legal liability or increased costs 67 Table of Content associated with those issues. For more information, see “—Issues in the use of AI (including machine learning) in our solutions may result in reputational harm, liability or impact our financial results.” Intellectual Property Our suite of solutions is based on proprietary software and related intellectual property rights. We rely on a combination of copyright, trademark and trade secret laws, as well as certain contractual provisions to establish, maintain, protect and enforce our intellectual property and other proprietary rights, including those relating to our technology and solutions. In addition, we license technology from third parties that is integrated into some of our solutions. We own a number of registered trademarks, including “Cellebrite”, “UFED” and other pending applications. Cellebrite also owns a number of domain names, including http://www.cellebrite.com. Recent Acquisitions In December 2025, we acquired Corellium, a U.S.-based provider of Arm-based Virtualization Software that empowers developers and security experts to research, work, and test seamlessly on an ever-expanding range of devices, from mobile smartphones to IoT and industrialized systems. We paid $170 million in cash (with $20 million converted into equity at closing). We will pay Corellium security holders up to an additional $30 million in cash based on the achievement of certain performance milestones over the next two years. In February 2026 we signed an agreement to acquire SCG Canada Inc., (“SCG”) a leading provider of hand-held digital forensics solutions that enables access to dozens of the most common Unmanned Aerial Vehicles (UAVs) for extraction, decoding and visualization of important forensic artifacts. On March 1, 2026 this acquisition was closed. We paid $17 million upon closing in cash, and an additional $1 million in RSUs to be vested in one year subject to Cellebrite’s common vesting conditions. Acquiring SCG is expected to further broaden Cellebrite’s digital forensics capabilities for collecting and reviewing data from a fast-growing category of digital witnesses. Legal Proceedings See “Part I, Item 8. Financial Information—A. Consolidated Statements and Other Financial Information—Legal Proceedings.” C. ORGANIZATIONAL STRUCTURE The Company was incorporated on April 13, 1999 under Israeli Law and has subsidiaries in the United States, Germany, Singapore, Australia, Brazil, United Kingdom, France, Canada, Japan and India, which are listed below: 68 Table of Content SUBSIDIARIES OF CELLEBRITE DI LTD. Name of Subsidiary Jurisdiction of Organization Cellebrite Inc. U.S. (Delaware) Cellebrite GmbH Germany Cellebrite Asia Pacific Pte Ltd. Singapore Cellebrite Soluções de Inteligência Digital Ltda Brazil Cellebrite Digital Intelligence Solutions Private Limited India Cellebrite UK Limited United Kingdom Cellebrite Canada Mobile Data Solutions Ltd. Canada Cellebrite France SAS France Cellebrite Japan K.K. Japan Cellebrite Australia PTY Limited Australia Cellebrite Digital Intelligence LP U.S. (Delaware) Cellebrite Federal Solutions Inc. U.S. (Delaware) Corellium, Inc. U.S. (Delaware) SCG Canada Inc. Canada All subsidiaries are 100% owned by Cellebrite DI Ltd., except: Cellebrite Canada Mobile Data Solutions Ltd., which is 100% owned by Cellebrite UK Limited, Cellebrite Digital Intelligence LP which is 99% owned by Cellebrite DI Ltd., and 1% owned by Cellebrite Inc., Cellebrite Digital Intelligence Solutions Private Limited which is 99.99% owned by Cellebrite DI Ltd and 0.01% owned by Cellebrite Asia Pacific Pte Ltd., Cellebrite Federal Solutions Inc. which is 100% owned by Cellebrite Inc. and Corellium, Inc. which is 100% owned by Cellebrite Inc. D. PROPERTY, PLANTS AND EQUIPMENT Our main offices are currently located in a 6,386 square meter facility that we lease in Petah-Tikva, Israel, where the premises are used for all aspects of our operations (except for our factory). Our lease for this facility expires on June 30, 2027. We also lease a 1,445 square meter facility in Kiryat Malachi, Israel where the premises are used for our hardware factory. Our lease for this facility expires on February 28, 2031. Our USA main offices are currently located in a 31,901 sq. ft facility that we lease in Mclean, VA, USA, where the offices are used for our sales, marketing and other go-to-market activities in the Americas. Our lease for this facility expires on June 30, 2036. In addition, we have offices in the following locations: Morristown, New Jersey; Delray Beach, Florida; Ottawa, Canada; Singapore; New Delhi, India; Tokyo, Japan; Sao Paulo, Brazil; London, UK; Munich, Germany, Tel Aviv, Israel and Jerusalem, Israel. Our offices support functions across sales and marketing, services, research and development, and operations and administration.
A. OPERATING RESULTS This operating and financial review should be read together with the section captioned “Selected Financial Data,” “Part I, Item 4, Information on the Company—B. Business Overview” and our consolidated financial statements and the related notes to those state…
A. OPERATING RESULTS This operating and financial review should be read together with the section captioned “Selected Financial Data,” “Part I, Item 4, Information on the Company—B. Business Overview” and our consolidated financial statements and the related notes to those statements prepared in accordance with U.S. GAAP and included elsewhere in this Annual Report. Among other things, those financial statements include more detailed information regarding the basis of preparation for the following information. This discussion contains forward-looking statements that involve risks and uncertainties. As a result of many factors, such as those set forth under “Part I, Item 3.D. Risk Factors” and elsewhere in this Annual Report, our actual results may differ materially from those anticipated in these forward-looking statements. Please see “Special Note About Forward-Looking Statements and Risk Factor Summary” in this Annual Report. Overview Cellebrite is a leading provider of AI-powered digital investigative and intelligence solutions that are designed to help public and private sector customers around the world transform their investigative workflows, make forensically sound digital data more accessible and actionable, and elevate the efficiency and effectiveness of mobile research and application security. Our solutions are designed to help law enforcement agencies protect their communities more effectively and efficiently by advancing investigations, and in that supporting these agencies in their efforts to successfully prosecute criminals, and exonerate the innocent. Defense and intelligence agencies use our solutions to enhance border security, advance counter terrorism and intelligence operations, conduct sensitive site exploitation, increase military readiness, and support cyber operations. Our software also enables enterprises and service providers to collect and review data in support of corporate investigations, eDiscovery and incidence response events, as well as to more efficiently and effectively design and validate next-generation mobile applications. For more information, see “Part I, Item 4. Information on the Company — B. Business Overview.” Our revenue was $475.7 million and $401.2 million for the years ended December 31, 2025 and 2024, respectively, representing a year-over-year increase of 19%. The increase in revenue period-over-period was driven by the following: (i) continued sales of our Inseyets suite of digital forensics software to existing customer base and to new customers; and (ii) continuous adoption of the rest of our portfolio of offerings such as Pathfinder and Guardian by our existing customer base. Net income (loss) of $78.3 million and $(283.0) million were incurred for the years ended December 31, 2025 and 2024, respectively, representing a period-over-period income increase of $361.3 million. This increase primarily reflects the impact of the financial expenses from presenting the Company’s Warrants, Restricted Sponsor Shares liability and Price Adjustment Shares liability at their fair value. Our Adjusted EBITDA for the years ended December 31, 2025 and 2024 was $127.6 million and $99.4 million, respectively and reflects the company’s continuous revenue growth coupled by prudent spending management. Acquisitions See “Part I, Item 4. Information on the Company—B. Business Overview—Recent Acquisitions.” 70 Table of Content Key Factors Affecting Our Performance Our historical financial performance has been, and we expect our financial performance in the future to be, mainly driven by our ability to: •Increase penetration within existing customers. We plan to continue to increase penetration within our existing customers with our AI-powered digital investigative and intelligence software solutions and by expanding the breadth of our solutions capabilities to provide for continued up-selling and cross-selling opportunities with both public and private sector customers. We have seen an increase in Annual Recurring Revenue (“ARR”) and dollar-based net retention due to the broad use cases of our software offerings with public sector and private sector customers. •Capitalize on the prioritization of law enforcement funding. We generate the majority of our revenue from contracts with national, regional and local governments to support an array of law enforcement agencies. We believe that ongoing funding of these law enforcement agencies will remain a top priority in the U.S. and in other countries around the world despite recent and ongoing geopolitical changes that have recently impacted the overall spending priorities of certain public sector customers and the timing and magnitude of their spending plans for our technology, As a result, we believe we are well-positioned to continue expanding our business with existing public sector customers and are investing accordingly. •Extend our technology and market leadership position. We continue to strengthen our position as a market-leading provider of AI-powered digital investigative and intelligence software solutions through investment in research and development and continued innovation. In addition to ongoing investment to enhance our mobile research capabilities, we plan to enhance and expand the functionality of our software solutions by investing in generative and agentic AI capabilities that will enable us to address a wider range of customer needs and mode of operation. We are also increasing our investment in SaaS and Cloud to address growing demand to use our solutions via these deployment options. We believe this strategy expands our addressable market, enables new growth opportunities and allows us to continue to deliver differentiated high-value outcomes to our customers. •Grow our customer base. Historically, new customer acquisition has represented a modest driver of top-line expansion due in large part to the fact that we have established long-term relationships with most of the largest public sector agencies and many of the largest enterprises and services providers in the private sector. However, while spending by new customers on our solutions starts at relatively modest levels, their spending grows over time at a rate that is generally in line with overall company. As a result, we believe that the acquisition of new customers in both the public sector, mainly with smaller accounts, and in the private sector, mainly with larger enterprise accounts and service providers, will continue to contribute modestly to the growth of our business. 71 Table of Content Key Metrics In addition to our U.S. GAAP financial information, we monitor the following key metrics and non-GAAP financial measure in order to help us measure and evaluate the effectiveness of our operations: Year Ended December 31, 2025 2024 ($ in millions) Annual recurring revenue (ARR) $481 $396 YoY ARR Growth 21% 25% Recurring revenue dollar-based net retention rate 116% 124% Adjusted EBITDA 127.6 99.4 Annual recurring revenue: ARR is defined as the annualized value of active term-based subscription license contracts, SaaS subscription contracts, and maintenance contracts related to other non-recurring in effect at the end of that period. Subscription license contracts and maintenance contracts for other non-recurring are annualized by multiplying a full month revenue as of the last month of the period by 12. Recurring revenue dollar-based net retention rate: Dollar-based net retention rate is calculated by dividing customer recurring revenue by base revenue. We define base revenue as annual recurring revenue we recognized from all customers with a valid license at the end of the equivalent quarter of the previous year. We define our customer revenue as the annual recurring revenue we recognized on the date of measurement from the same customer base included in our measure of base revenue, including annual recurring revenue resulting from additional sales to those customers. Operating Income: Operating Income is calculated as Revenue less cost of revenue expenses and operating expenses. Non-GAAP Operating Income: Non-GAAP Operating Income is calculated as Operating Income plus issuance expenses, executive severance costs, share-based compensation expenses, amortization of intangible assets, and acquisition related costs. The following table provides a reconciliation of our operating income to Non-GAAP operating income: Year Ended December 31, 2025 2024 ($ in thousands) Operating income $ 66,480 $ 56,906 Executive severance costs 574 1,068 Share-based compensation expense 44,892 30,575 Amortization of intangible assets 4,899 3,349 Acquisition related costs 3,818 221 Non-GAAP operating income $ 120,663 $ 92,119 72 Table of Content Adjusted EBITDA: Adjusted EBITDA is calculated as net income plus financial expense, tax expense, depreciation expenses, amortization of intangible assets, issuance expenses, executive severance costs, share-based compensation expense, acquisition related costs. The following table provides a reconciliation of our net income to Adjusted EBITDA: Year Ended December 31, 2025 2024 ($ in thousands) Net income (loss) $ 78,326 $ (283,007) Financial (income) expense (24,198) 332,890 Tax expense 12,352 7,023 Depreciation expenses 6,968 7,258 Amortization of intangible assets 4,899 3,349 Executive severance costs 574 1,068 Share-based compensation expense 44,892 30,575 Acquisition related costs 3,818 221 Adjusted EBITDA 127,631 99,377 Adjusted EBITDA margin 27 % 25 % We believe that the use of non-GAAP operating income and Adjusted EBITDA is helpful to investors. These measures, which we refer to as our non-GAAP financial measures, are not prepared in accordance with GAAP. We believe that the non-GAAP financial measures provide a more meaningful comparison of its operational performance from period to period, and offer investors and management greater visibility into the underlying performance of its business: •Share-based compensation expenses utilize varying available valuation methodologies, subjective assumptions and a variety of equity instruments that can impact a company’s non-cash expenses; •Acquired intangible assets are valued at the time of acquisition and are amortized over an estimated useful life after the acquisition; •Acquisition-related expenses and executive severance expenses relate to the cash component of contractual severance due to our former CEO and CFO, all of which are unrelated to current operations and neither are comparable to the prior period nor predictive of future results; •To the extent that the above adjustments have an effect on tax (income) expense, such an effect is excluded in the non-GAAP adjustment to net income; •Tax expense, depreciation and amortization expense vary for many reasons that are often unrelated to our underlying performance and make period-to-period comparisons more challenging; and •Financial instruments are remeasured according to GAAP and vary for many reasons that are often unrelated to our current operations and affect financial income. 73 Table of Content Free Cash Flow: Free cash flow is calculated as net cash provided by or used in operating activities less purchases of property and equipment. We believe that free cash flow is a useful indicator of liquidity that provides information to management and investors about the amount of cash provided by or used in our operations that, after the investments in property and equipment, can be used for strategic initiatives. Year Ended December 31, 2025 2024 ($ in thousands) Net cash provided by operating activities $ 173,544 $ 132,171 Purchases of property and equipment (13,225) (8,566) Free cash flow 160,319 123,605 Free cash flow margin 34 % 31 % Key Components of Results of Operations Revenue Revenue consists of subscription, other non-recurring, and professional services. •Subscription. Subscription revenue include SaaS and on-premise subscription revenue, as well as maintenance and support services associated with on-premise subscriptions and other non-recurring arrangements. Subscription revenue is comprised of subscription services and term-license revenue. Subscription services revenue is the revenue that is recognized over the life of the subscription and term-license revenue is the revenue that is immediately recognized upon the sale of an on-premise subscription license. In connection with our term-based agreements, SaaS subscription agreements, and other non-recurring arrangements, we generate revenue through maintenance and support under renewable subscription, fee-based contracts that include unspecified software updates and upgrades released when and if available as well as software patches and support. Customers with active subscriptions are also entitled to our technical customers’ support. •Other non-recurring. Other non-recurring revenue reflects the revenue recognized from sales of other non-recurring related to offerings such as hardware sold mainly in connection with new software license, and usage-based fees. Other non-recurring fees are recognized upfront assuming all revenue recognition criteria are satisfied. •Professional Services. Professional Services consists of revenue related to: (i) certified training sessions by Cellebrite Trainings; (ii) our advanced services; (iii) certain implementation services in connection with our software licenses; (iv) on premise contracted customer success and technical support; and (v) specific on-site services contracted by us with customers and delivered by our personnel to support the ongoing operation of our solutions in collaboration with the customer. The revenue of professional services is recognized upon the delivery of our services. Cost of Revenue Cost of revenue consists of cost of subscription, cost of other non-recurring, and cost of professional services. •Cost of Subscription. Cost of subscription revenue includes all direct cost to deliver and support subscription services, including salaries and related employees’ expenses, allocated overhead such as facilities expenses, third party license fees, fees paid to OEMs, hosting, and IT related expenses. We recognize these costs and expenses upon occurrence. 74 Table of Content •Cost of other non-recurring. Cost of other non-recurring revenue includes all direct costs to deliver other non-recurring revenue, including HW costs, fees paid for third party products, materials, salaries and related employees’ expenses, allocated overhead such as depreciation of equipment and IT related expenses, warehouse, manufacturing and supply chain costs. We recognize these costs and expenses upon occurrence, while HW components are recognized upon delivery. •Cost of Professional Service. Cost of professional service revenue includes salaries and related employees’ expenses, subcontractors and all direct costs related to professional services such as services materials, allocated overhead such as depreciation of equipment, facilities and IT related costs. We recognize these costs and expenses upon occurrence. Gross Profit and Gross Margin Gross profit is revenue less cost of revenue, and gross margin is gross profit as a percentage of revenue. Gross profit has been and will continue to be affected by various factors, including our revenue mix, the selling price to our customers, the cost of our manufacturing facility, supply chain, hosting, salaries, other related costs to our employees and subcontractors and overhead. We expect that our gross margin will fluctuate from period to period depending on the interplay of these various factors. Operating Expenses Operating expenses consists of research and development, sales and marketing and general and administrative expenses. The most significant components of our operating expenses are personnel costs, which is included in each component of operating expenses and consists of salaries, benefits, bonuses, stock-based compensation and, with regards to sales and marketing expenses, sales commissions. •Research and development. Research and development expenses primarily consist of the cost of salaries and related costs for employees, subcontractors cost, consultation services and depreciation of equipment. Our costs of research and development also include facility-related expenses, recruitment and training, IT infrastructure, information system licenses, hosting, support and others that contribute to the research and development operations. We focus our research and development efforts on developing new solutions, core technologies and to further enhance the functionality, reliability, performance and flexibility of existing solutions. We believe that our software development teams and our core technologies represent a significant competitive advantage for us and we expect that our research and development expenses will continue to increase, as we invest in research and development headcount to further strengthen and enhance our solutions •Sales and marketing. Sales and marketing expenses primarily consist of the cost of salaries and related costs for employees, marketing activities, travel expenses, and commissions earned by our sales personnel. Our costs of sales and marketing also include facility-related expenses, recruitment and training, information system licenses, hosting, support and others that contribute to the sales and marketing operations. We expect that sales and marketing expenses will continue to increase as we continue to invest in our Go-to-Market activities. •General and administrative. General and administrative expenses primarily consist of the cost of salaries and related costs for employees, insurance, consultants and facility-related costs for our corporate management, finance, legal, IT, human resources, administrative personnel, and other corporate expenses. We anticipate moderate growth in our general and administrative expenses as we further expand our business around the world. All of the departments are allocated with general and administrative expenses such as rent and related expenses, recruitment and training, information systems licenses, hosting, support and others. 75 Table of Content Quarterly Trends in Operating Expenses Operating expenses have generally increased sequentially as a result of our growth and are primarily related to increases in personnel-related costs, including share-based compensation, to support the expanded operations, continued investment in research and development, and expansion of commercial and marketing investments. Financial Income (expense), Net Financial income (expense), net consists primarily interest income on our short-term deposits, fees to banks and foreign currency realized and unrealized income and loss related to the impact of transactions denominated in a foreign currency and financial investment activities, and revaluation of derivative warrant liability, Restricted Sponsor Shares and Price Adjustment Shares. Tax Expense Tax expense (as well as deferred tax assets and liabilities, and liabilities for unrecognized tax benefits) reflect management’s best assessment of estimated current and future taxes to be paid. We are subject to income taxes in Israel, the United States, and numerous other foreign jurisdictions. Significant judgments and estimates are required in determining the consolidated income tax expense. Our income tax rate varies from Israel’s statutory income tax rates, mainly due to differing tax rates and regulations in foreign jurisdictions and other differences between expenses and expenses recognized by other tax authorities in relevant jurisdictions. We expect this fluctuation in income tax rates, as well as its potential impact on our results of operations, to continue. Results of Operations The following tables and narrative set forth our results of operations for the periods presented. For a comparison of our results of operations for the years ended December 31, 2024 and 2023, see “Part I, Item 5. Operating and Financial Review Prospects—A. Operating Results” in our Annual Report on Form 20-F for the fiscal year ended December 31, 2024, filed with the SEC on March 18, 2025, which comparative information is herein incorporated by reference. 76 Table of Content Year ended December 31, 2025 2024 ($ in thousands) Revenue: Subscription services $ 330,765 $ 271,028 Term-license 96,245 82,007 Other non-recurring 17,771 17,285 Professional services 30,894 30,883 Total Revenue 475,675 401,203 Cost of revenue: Cost of subscription services 37,461 26,004 Cost of term-license 87 — Cost of other non-recurring 15,617 16,200 Cost of professional services 22,007 20,389 Total cost of revenue 75,172 62,593 Gross profit $ 400,503 $ 338,610 Operating expenses: Research and development 113,877 98,415 Sales and marketing 154,814 132,389 General and administrative 65,332 50,900 Total operating expenses 334,023 281,704 Operating income 66,480 56,906 Financial income (expense), net 24,198 (332,890) Income (loss) before tax expenses 90,678 (275,984) Tax expense 12,352 7,023 Net income (loss) $ 78,326 $ (283,007) Other comprehensive income Unrealized income (loss) on hedging transactions, net of tax 1,115 (487) Unrealized income on marketable securities 317 113 Foreign currency translation adjustments (1,298) 1,410 Total other comprehensive income, net of tax 134 1,036 Total comprehensive income (loss) $ 78,460 $ (281,971) Results of operations includes share-based compensation expenses: Year ended December 31, 2025 2024 ($ in thousands) Cost of revenue $ 3,180 $ 2,227 Research and development 10,008 6,663 Sales and marketing 13,861 $ 10,216 General and administrative 17,843 11,469 Total share-based compensation $ 44,892 $ 30,575 77 Table of Content Revenue Year Ended December 31, Change 2025 2024 Amount Percent ($ in thousands) Subscription services $ 330,765 $ 271,028 $ 59,737 22% Term-license 96,245 82,007 14,238 17% Total subscription 427,010 353,035 73,975 21% Other non-recurring 17,771 17,285 486 3% Professional services 30,894 30,883 11 —% Total Revenue $ 475,675 $ 401,203 $ 74,472 19% Subscription Subscription revenue increased by $74.0 million, or 21% for the year ended December 31, 2025, as compared with the year ended December 31, 2024, primarily due to an increase related to the continuous adoption of our solutions primarily by existing customers and, to lesser extent, new customers. Other non-recurring Other non-recurring revenue increased by $0.5 million, or 3%, for the year ended December 31, 2025, as compared with the year ended December 31, 2024, primarily due to the sale of hardware components sold in conjunction with the sale of new licenses of our Inseyets suite of digital forensics offerings and the Pathfinder on-premise solutions. Professional Services Professional services revenue remained consistent for the year ended December 31, 2025, as compared with the year ended December 31, 2024, primarily due to reduced demand for Cellebrite Advanced Services as more customers adopted our advanced lawful access solutions, offset by an increase of training revenue. Cost of Revenue Year Ended December 31, Change 2025 2024 Amount Percent ($ in thousands) Cost of subscription services $ 37,461 $ 26,004 $ 11,457 44 % Cost of term-license 87 — 87 100 % Cost of other non-recurring 15,617 16,200 (583) (4 %) Cost of professional services 22,007 20,389 1,618 8 % Cost of Revenue $ 75,172 $ 62,593 $ 12,579 20 % 78 Table of Content Cost of Subscription Cost of subscription increased by $11.5 million, or 44% for the year ended December 31, 2025, as compared to the year ended December 31, 2024. This increase is primarily due to expenses related to additional subscription revenue, such as hosting expenses, customer support and customer success personnel expenses. Cost of Other Non-Recurring Cost of other non-recurring revenue decreased by $0.6 million, or 4% for the year ended December 31, 2025, as compared with the year ended December 31, 2024. This decrease is primarily due to hardware costs. Cost of Professional Services Cost of professional services revenue increased by $1.6 million, or 8% for the year ended December 31, 2025, as compared with the year ended December 31, 2024. The increase is primarily due to increased training expenses. Gross Profit and Gross Profit Margin Year Ended December 31, Change 2025 2024 Amount Percent ($ in thousands) Gross Profit: Subscription services $ 293,304 $ 245,024 $ 48,280 20 % Term-license 96,158 82,007 14,151 17 % Total subscription 389,462 327,031 62,431 19 % Other non-recurring 2,154 1,085 1,069 99 % Professional services 8,887 10,494 (1,607) (15 %) Total gross profit $ 400,503 $ 338,610 $ 61,893 18 % Gross Profit Margins: Subscription services 89 % 90 % Term-license 100 % 100 % Total subscription 91 % 93 % Other non-recurring 12 % 6 % Professional services 29 % 34 % Total gross margin 84 % 84 % Subscription Subscription gross profit increased by $62.4 million, or 19%, during the year ended December 31, 2025, as compared with the year ended December 31, 2024. Subscription gross profit margin decreased from 92.6% to 91.2%, during the year ended December 31, 2025, as compared with the year ended December 31, 2024, mainly due to an increase in hosting expenses and customer success personnel expenses. 79 Table of Content Other non-recurring Other non-recurring gross profit increased by $1.1 million, or 99%, during the year ended December 31, 2025, as compared with the year ended December 31, 2024. Other non-recurring gross profit margin increased from 6% to 12%, during the year ended December 31, 2025, as compared with the year ended December 31, 2024, mainly as a result of higher hardware revenue in 2025 and decreased costs. Professional Services Professional services gross profit decreased by $1.6 million, or 15% during the year ended December 31, 2025, as compared with the year ended December 31, 2024. Services gross profit margin decreased from 34% to 29%, during the year ended December 31, 2025, as compared with the year ended December 31, 2024, mainly as a result of lower Cellebrite advanced services revenue and increased training expenses. Operating Expenses Year EndedDecember 31 Change 2025 2024 Amount Percent ($ in thousands) Operating expenses Research and development 113,877 98,415 15,462 16 % Sales and marketing 154,814 132,389 22,425 17 % General and administrative 65,332 50,900 14,432 28 % Total operating expenses $ 334,023 $ 281,704 $ 52,319 19 % Research and development Research and development expenses increased by $15.5 million, or 16%, for the year ended December 31, 2025, as compared with the year ended December 31, 2024. This increase is primarily attributable to an increase in salaries and related costs of $12.2 million, and hosting costs of $1.0 million. Sales and marketing Sales and marketing expenses increased by $22.4 million, or 17%, for the year ended December 31, 2025, as compared to the year ended December 31, 2024. The increase primarily relates to higher salaries and related costs for employees and commissions earned by our sales personnel of $15.2 million and a $2.5 million increase in marketing activities. General and administrative General and administrative expenses increased by $14.4 million, or 28%, for the year ended December 31, 2025, as compared with the year ended December 31, 2024. The increase primarily relates to salaries and related costs for employees of $15.9 million, of which $9.4 million was associated with share-based compensation, mainly related to the Company’s CEO grants of $7.2 million, offset by hosting expense decreases. 80 Table of Content Finance Income (expense), net Finance income (expense), net increased by $357.1 million, or 107%, for the year ended December 31, 2025, as compared with the year ended December 31, 2024, mainly due to revaluation of derivative warrants, sponsors restricted shares and price adjustment shares derived expenses in 2024, due to the increase in the Company’s share price. These instruments were no longer classified as liabilities in 2025. Taxes on Income Taxes on income increased by $5.3 million, or 76%, for the year ended December 31, 2025, as compared with the year ended December 31, 2024, mainly as a result of profit for tax position in the Parent Company. For additional information regarding Israeli corporate tax, see - “Part I, Item 10. Additional Information — E. Material U.S Federal Income Tax Considerations —Non-U.S Holders - Tax Benefits Subsequent to the 2005 Amendment.” B.Liquidity and Capital Resources The following tables and narrative set forth our results of operations for the periods presented. For a discussion of our cash flows for the year ended December 31, 2023, see “Part I, Item 5. Operating and Financial Review Prospects—B. Liquidity and Capital Resources” in our Annual Report on Form 20-F for the fiscal year ended December 31, 2024, filed with the SEC on March 18, 2025, which comparative information is herein incorporated by reference. Our cash, cash equivalents, short-term deposits and marketable securities were $535.0 million and $483.8 million as of December 31, 2025 and December 31, 2024, respectively. We derive our cash primarily from our business operations. Currently, our primary liquidity needs are employee salaries and benefits, product development, and other operating activities to support our organic growth, and our operating cash requirements may increase in the future as we continue to invest in the growth of our company. During the fiscal years ended December 31, 2025 and 2024, our capital expenditures amounted to $13.2 million and $8.6 million, respectively, primarily consisting of expenditures related to property and equipment and software, and we expect that our capital expenditures for the next 12 months will relate to the same needs. We may also enter into future arrangements to acquire or invest in businesses, products, services, strategic partnerships, and technologies. We believe that our existing cash and cash equivalents, short-term investments and cash flows from operations will be sufficient to fund our organic operations and capital expenditures for at least the next 12 months. Our future capital requirements will depend on many factors, including our rate of revenue growth, timing of renewals and subscription renewal rates, the expansion of our sales and marketing activities, the timing and extent of spending to support product development efforts and expansion into new customer base, the timing of introductions of new software products and enhancements to existing software products, and the continuing market acceptance of our software offerings and our use of cash to pay for acquisitions. We may be required to seek additional equity or debt financing. In the event that additional financing is required from outside sources, we may not be able to raise it on terms acceptable to us or at all. Credit Facilities We do not have any credit facilities. 81 Table of Content Cash Flows Year Ended December 31, 2025 2024 ($ in thousands) Net cash provided by operating activities $ 173,544 $ 132,171 Net cash used in investing activities $ (268,250) $ (149,473) Net cash provided by financing activities $ 25,053 $ 20,651 Operating Activities For the year ended December 31, 2025, cash provided by operating activities was $173.5 million, mainly as a result of increasing in our non-GAAP operating income and the increase in deferred revenue. For the year ended December 31, 2024, cash provided by operating activities was $132.2 million, mainly as a result of our non-GAAP operating income, the increase in deferred revenue and the increase in other accounts payable and accrued expenses associate with year-end compensation accruals, withholding tax associated with share-based compensation vesting and exercise and consultancy services. Investing Activities Cash used in investing activities in the year ended December 31, 2025 was $268.3 million, primarily as a result of the net investment in marketable securities of $108.4 million. We acquired Corellium Inc. for a net payment of $147.5 million and invested in property and equipment in the amount of $13.2 million. Cash used in investing activities in the year ended December 31, 2024 was $149.5 million, primarily as a result of the net investment in marketable securities of $67.8 million and maturities of short-term deposits, net of $68.3 million. We acquired CyTech Inc. for a net payment of $2.7 million and invested in property and equipment and intangible assets in the amount of $10.6 million. Financing Activities Cash provided by financing activities in the year ended December 31, 2025 was $25.1 million, mainly as a result of proceeds from exercise of stock options to shares of $20.1 million and proceeds from Employee Share Purchase Plan of $5 million. Cash provided by financing activities in the year ended December 31, 2024 was $20.7 million, mainly as a result of proceeds from exercise of stock options to shares of $17.3 million and proceeds from Employee Share Purchase Plan of $3.3 million. Contractual Obligations and Commitments As of December 31, 2025, we had commitments of $28.7 million related to office and car leases arrangements, that we cannot cancel or where we would be required to pay a termination fee in the event of cancellation. Payments under these commitments are estimated to be made as follows: 82 Table of Content (In thousands of U.S. dollars) Payments (1) Less than 1 year $ 4,556 1-3 years 6,835 3-5 years 4,912 More than 5 years 12,382 Total $ 28,685 (1) Amounts do not include recourse that we may have to pay to recover termination fees or penalties from clients. Off-Balance Sheet Arrangements There are no off-balance sheet arrangements to which the Company is committed. Quantitative and Qualitative Disclosures About Market Risk We are exposed to market risk in the ordinary course of our business. Market risk represents the risk of loss that may impact our financial position due to adverse changes in financial market prices and rates. Our market risk exposure is primarily a result of fluctuations in foreign currency exchange rates, interest rates and inflation. Foreign Currency Exchange Risk Our revenue and expenses are primarily denominated in U.S. dollars and NIS and to a lesser extent, other currencies in our relevant subsidiaries. As some of our sales are denominated in non-U.S. dollars currencies, our revenue is subject to foreign currency risk. In addition, a significant portion of our operating costs in Israel, consisting mainly of salaries and related personnel expenses are denominated in NIS. This foreign currency exposure gives rise to market risk associated with exchange rate movements of the U.S. dollar against the NIS. Furthermore, we anticipate that a meaningful portion of our expenses will continue to be denominated in NIS. To reduce the impact of foreign exchange risks associated with forecasted future cash flows and the volatility in our consolidated statements of operations, we have established a hedging program. Our foreign currency contracts are generally short-term in duration. We do not enter into Derivative Instruments for trading or speculative purposes. We account for our Derivative Instruments as either assets or liabilities and carry them at fair value in the consolidated balance sheets. The accounting for changes in the fair value of the derivative depends on the intended use of the derivative and the resulting designation. Our hedging program reduces but does not eliminate the impact of currency exchange rate movements. The effect of a hypothetical 10% change in foreign currency exchange rates applicable to our business, after considering cash flow hedges, would have had an impact on our results of operations of $6.4 million and $9.5 million, for the year ended December 31, 2025 and 2024, respectively. Our derivatives expose us to credit risk to the extent that the counterparties may be unable to meet the terms of the agreement. We seek to mitigate such risk by limiting our counterparties to major financial institutions and by spreading the risk between two major financial institutions. However, failure of one or more of these financial institutions is possible and could result in incurred losses. As of December 31, 2025, our cash, cash equivalents and short-term investments were primarily denominated in U.S. dollars. A 10% increase or decrease in current exchange rates would have affected our cash, cash equivalents, restricted cash, and short-term investment balances in amount of $2.4 million and $2.6 million as of December 31, 2025 and 2024, respectively. 83 Table of Content Interest Rate Risk As of December 31, 2025, we had cash and cash equivalents of $124.5 million, short-term deposits of $161.0 million and short-term investments in marketable securities of $151.5 million. Cash and cash equivalents consist of cash in banks, bank deposits for a period up to 3 months, and money market funds. Short-term investments generally consist of bank deposits for a period greater than 3 months and marketable securities. Our cash and cash equivalents are held for working capital purposes, while our short-term investments are mainly held for strategic purposes. Interest-earning instruments carry a degree of interest rate risk. The primary objectives of our investment activities are the preservation of capital, the fulfillment of liquidity needs and the fiduciary control of cash. We do not enter into investments for trading or speculative purposes. A hypothetical 1% change in interest rates during any of the periods presented would not have had a material impact on our financial income for the year ended December 31, 2025. Inflation Risk Inflationary factors, such as increases in our cost of goods sold, may adversely affect our operating results. Although, recent elevated levels of inflation in the global and U.S. economies have not had a significant impact on our results of business, financial condition, or operations, a high rate of inflation in the future may have an adverse effect on our ability to maintain and increase our gross profit if the selling prices of our products do not increase as much or more than these increased costs. If elevated levels of inflation persist or increase, our business, financial condition, or operations could be adversely affected, particularly in certain global markets. Additionally, most of our sales are denominated in U.S. dollars, EUR or GBP, which have not been subject to material currency inflation, and our operating expenses are denominated in NIS and U.S. dollar and have not been subject to material currency inflation. C. RESEARCH AND DEVELOPMENT, PATENTS AND LICENSES, ETC. Our research and development spending totaled $113.9 million, $98.4 million and $84.4 million for the years ended December 31, 2025, 2024 and 2023 respectively. As described in “Part I, Item 3. Key Information—3.D. Risk Factors” and elsewhere in this Annual Report, government regulations and policies can make developing or marketing new technologies expensive or uncertain due to various restrictions on trade and technology transfers. See “Part I, Item 3. Key Information—D. Risk Factors” and “Part I, Item 4. Information on the Company—B. Business Overview—Regulations.” For further information on our research and development policies and additional product information, see “ Part I, Item 4. Information on the Company— B. Business Overview.” D. TREND INFORMATION See “Part I, Item 5. Operating and Financial Review Prospects—A. Operating Results” and “Part I, Item 5. Operating and Financial Review Prospects—B. Liquidity and Capital Resources,” which are incorporated by reference herein. E. CRITICAL ACCOUNTING ESTIMATES The preparation of consolidated financial statements in conformity with U.S. generally accepted accounting principles requires management to make estimates and assumptions that affect the reported amounts of assets and liabilities and disclosure of contingent assets and liabilities at the date of the consolidated financial statements and the reported amounts of revenue and expenses during the reporting period. Actual results could differ from those estimates. 84 Table of Content Please see Notes to Consolidated Financial Statements included in Item 18 of this Annual Report on Form 20-F for a summary of significant accounting policies and the effect on our financial statements. Revenue Recognition We sell our products and services to our customers either directly or indirectly through distribution channels all of whom are considered end customers. For contracts that contain multiple performance obligations, we allocate the transaction price to each performance obligation based on the relative standalone selling price (“SSP”). We use judgment in determining the SSP for its products and services. We typically assess the SSP for its products and services on a periodic basis or when facts and circumstances change. To determine SSP, we maximize the use of observable standalone sales and observable data, where available. In instances where performance obligations do not have observable standalone sales, we utilize available information that may include the entity specific factors such as assessment of historical data of bundled sales of software licenses with other promised goods and services, and pricing strategies to estimate the price we would charge if the products and services were sold separately. We satisfy performance obligations either over a time period or at a point in time depending on the nature of the underlying promise. Revenue is recognized at the time the related performance obligation is satisfied by transferring a promised good or service to a customer. Revenue related to the license for proprietary software is recognized when the control over the license is provided to the customer and the license term begins. Revenue related to software update and upgrades are recognized ratably over the service period. Revenue related to professional services are recognized as services are performed, using the method that best depicts the transfer of services to the customer. Business combination The Company applies the provisions of ASC 805, “Business Combination” and allocates the fair value of purchase consideration to the tangible assets acquired, liabilities assumed, and intangible assets acquired based on their estimated fair values. The excess of the fair value of purchase consideration over the fair values of these identifiable assets and liabilities is recorded as goodwill. When determining the fair values of assets acquired and liabilities assumed, the Company estimated the future expected cash flows from acquired core technology and acquired trade name from a market participant perspective, useful lives and discount rates. In addition, management makes significant estimates and assumptions, which are uncertain, but believed to be reasonable. Significant estimates in valuing certain intangible assets include, but are not limited to future expected cash flows from acquired intangible assets from a market participant perspective, useful lives and discount rates. Management’s estimates of fair value are based upon assumptions believed to be reasonable, but which are inherently uncertain and unpredictable and, as a result, actual results may differ from estimates. Acquisition-related costs are recognized separately from the acquisition and are expensed as incurred. Merger On April 8, 2021, TWC, Cellebrite and Merger Sub entered into the Merger Agreement providing for, upon the terms and subject to the conditions thereof, the Merger between TWC and Cellebrite pursuant to which, among other things, Merger Sub merged with and into TWC at the Effective Time (as defined in the Merger Agreement), with TWC continuing as the surviving entity and as a wholly-owned subsidiary of Cellebrite. The Merger closed on August 30, 2021. The Merger was accounted for as a recapitalization, with no goodwill or other intangible assets recorded, in accordance with U.S. GAAP. 85 Table of Content Under this method of accounting, Cellebrite has been determined to be the accounting acquirer. The combined entity is the successor SEC registrant, meaning that Cellebrite’s financial statements for previous periods will be disclosed in the registrant’s future periodic reports filed with the SEC. In December 2023, TWC was dissolved. As a consequence of the Merger, the Ordinary Shares are registered under the Exchange Act and listed on Nasdaq, and we were required to hire additional personnel and implement procedures and processes to address public company regulatory requirements and customary practices. We have incurred, and expect to incur, additional annual expenses as a public company for, among other things, directors’ and officers’ liability and board of directors related expenses. Recent Accounting Pronouncements See the Summary of Significant Accounting Policies, included in our audited consolidated statements included in this Annual Report for a description of recently issued accounting pronouncements. 86 Table of Content