← Back to CDNS filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
Our operations and financial results are subject to various risks and uncertainties, including those described in the “Risk Factors” sections in our Annual Report and this Quarterly Report, that could adversely affect our business, financial condition, results of operations, cash flows, liquidity, revenue, growth, prospects, demand, reputation, and the trading price of our common stock, and make an investment in us speculative or risky. We have updated two of the risk factors since our Annual Report, as set forth in our Quarterly Report on Form 10-Q for the quarterly period ended March 31, 2026 and below. The risks described in our Annual Report and this Quarterly Report do not include all of the risks that we face, and there may be additional risks or uncertainties that are currently unknown or not believed to be material that occur or become material.
Uncertainty in the global economy and instability within international relations, including changes in governmental policies relating to technology, may negatively affect our business and reduce our bookings levels and revenue.
Uncertainty caused by challenging global political and economic conditions, including inflation, interest rates, bank failures, government deficit concerns, government shutdowns or political stalemates, geopolitical conflicts and other adverse changes to international relationships among countries in which we or our customers operate or do business, protectionist measures or decline in corporate or consumer spending could negatively impact our customers’ businesses, reducing the number of new chip designs and their overall research and development spending, including their spending on our products and services, and as a result decrease demand for our products and services. Adverse developments that affect financial institutions, transactional counterparties or other third parties, such as bank failures and failure by the U.S. Congress to increase the U.S. federal debt ceiling on a timely basis, or concerns or speculation about any similar events or risks, have led and could lead to further credit downgrades and market-wide liquidity problems, which in turn may cause customers and other third parties to become unable to meet their obligations under various types of financial arrangements as well as general disruptions or instability in the financial markets. Public health emergencies and reactionary measures by governments and businesses have also had, and could in the future have, the effect of curtailing economic activity and causing substantial volatility and disruption in global markets. Decreased bookings for our products and services, customer bankruptcies, consolidation among our customers, or problems or delays with our hardware suppliers or with the supply or delivery of our hardware products could also adversely affect our ability to grow our business or adversely affect our future revenue and financial results.
Tensions are rising around the world, and there are a number of ongoing armed conflicts, including in Iran, other parts of the Middle East and Ukraine. There is inherent risk, based on the complex relationships between certain countries and within regions, that political, diplomatic or military events could result in trade disruptions and other disruptions in the markets and industries we serve and our supply chain. A significant disruption in any area where we or our customers operate or do business or that is critical to our or their supply chain could reduce customer demand, make our products and services more expensive or unavailable for customers, increase the cost of our products and services, have a negative impact on customer spending, make our products less competitive, or otherwise have a materially adverse impact on our future revenue and profits, our customers’ and suppliers’ businesses, and our results of operations. In addition, there is currently significant uncertainty in the global economy and the future relationship among the United States and various other countries, caused by increased geopolitical instabilities and changes in global trade policies. For example, the ongoing geopolitical and economic uncertainty between the United States and China, where we conduct business and have derived a substantial percentage of our revenue, the unknown impact of current and future U.S. and Chinese trade regulations, including tariffs and other trade restrictions, and geopolitical risks with respect to Taiwan, which serves as a central hub for the technology industry supply chain, could, directly or indirectly, materially harm our business, financial condition and results of operations. Similarly, many of our suppliers, vendors and other entities with whom we do business have strong ties to doing business in China and other countries impacted by recent tariffs and other trade restrictions. Their ability to supply materials to us, buy products or services from us, or otherwise work with us is affected by their ability to do business in impacted countries. Moreover, these tariffs and any other trade restrictions imposed on our suppliers could adversely affect our business, financial condition and results of operations through reduced demand for our products and services, cancelled orders, supply chain disruptions, increased transaction costs and increased expenses.
Our future business and financial results, including demand for our products and services, are subject to considerable uncertainties that could impact our stock price. Further, political or economic conflicts between various global actors, and responsive measures that have been or could be taken, have created and can further create significant global economic uncertainty that could prolong or expand such conflicts, which could have a lasting impact on regional and global economies and harm our business and operating results.
38
Cyberattacks that compromise the confidentiality, integrity or availability of our or our third-party providers' information technology systems or confidential information could materially harm our reputation, business, financial condition and results of operations.
We rely on hardware, software, digital infrastructure and computing networks for both internal and customer-facing operations that are critical to our business (collectively, “IT Systems”). We own and manage certain IT Systems but also rely on third parties for IT Systems and related products and services, including cloud computing. In addition, we and certain third-party providers collect, maintain and process data about our customers, employees, business partners and others, including information that relates to individuals and/or constitutes “personal data,” “personal information,” "personally identifiable information" or similar terms under applicable data privacy laws (collectively “Personal Information”), as well as proprietary data such as trade secrets (together with Personal Information, “Confidential Information”).
We face numerous, evolving cybersecurity risks that threaten the confidentiality, integrity and availability of our IT Systems, Confidential Information, products and services, including from diverse threat actors, such as state-sponsored organizations, opportunistic hackers and malicious insiders, as well as through diverse attack vectors, such as social engineering (including phishing), malware (including ransomware) and denial-of-service attacks, and due to human or technological error, such as misconfigurations, “bugs” or other vulnerabilities in software or hardware. Additionally, advances in technology, an increased level of sophistication and expertise of hackers, widespread access to generative AI, and new discoveries in the field of cryptography increase the risk of significant compromises or breaches of our IT Systems or security measures implemented to protect our systems. From time to time, we and certain of our third-party service providers experience varying degrees of cyberattacks and other security incidents. Any such incidents could compromise our or our providers' IT Systems, which could cause system disruptions or slowdowns and lead to the Confidential Information stored on our or third-party systems being accessed, publicly disclosed, lost or stolen. Any actual or perceived unauthorized access or disclosure to our Confidential Information poses significant risk to our business as it could result in reputational and financial harm and further subject us to liability to our customers, suppliers, business partners and others. For example, as described in our Quarterly Report on Form 10-Q for the period ended March 31, 2026, we learned that a threat actor obtained a limited amount of Confidential Information from certain of our IT systems including a limited amount of test files, configuration setting files and source code files which are not material to our business. We notified law enforcement, and we believe that the incident was contained. There was no operational disruption, and customer environments were not impacted.
Cyberattacks are expected to accelerate on a global basis in frequency and magnitude as threat actors are becoming increasingly sophisticated in using techniques and tools – including AI – that circumvent security controls, evade detection and remove forensic evidence. Techniques used to obtain unauthorized access or to sabotage information systems change frequently and include zero-day software vulnerabilities that are unknown until exploited by threat actors. As a result, we may be unable to promptly or effectively detect, investigate, remediate or recover from future attacks or incidents, or to avoid a material adverse impact to our IT Systems, Confidential Information or business. Furthermore, state-supported and geopolitical-related cyberattacks against companies such as ours may increase due to geopolitical conditions. A cyberattack on our IT Systems or IT Systems of one of our third-party providers or customers could result in material adverse impacts due to any or all of the following: compromise to our Cadence Cloud portfolio, which includes both our managed and customer-managed environments, and our data centers and those of our customers and end users; corruption or stealing of Confidential Information such as proprietary information related to our (or our customers') business, products, services and infrastructure or Personal Information; manipulation or stealing of financial data and assets; and/or disruption of our systems and services and those of our customers and others. As a result, we could be exposed to a risk of loss or misuse of Confidential Information, loss of financial assets, business interruption, regulatory investigations, litigation and other liabilities and costs.
Because we make extensive use of third-party suppliers and service providers, such as cloud services that support our internal and customer-facing operations, successful cyberattacks that disrupt or result in unauthorized access to third party providers’ IT Systems, including those that store our Confidential Information, can materially impact our operations and financial results. Moreover, hardware, software or applications we develop or procure from third parties or through open source solutions may contain defects in design or manufacture or other vulnerabilities and are susceptible to compromise. In addition, we have acquired and continue to acquire companies with less sophisticated security measures, and it takes time to align their security practices to meet our information security policies, procedures and controls, which exposes us to increased cybersecurity and other integration risks. There can be no assurance that our cybersecurity risk management strategy, program, policies, processes and controls will be fully implemented, complied with or effective in protecting any systems or information.
An actual or perceived breach of IT Systems or Confidential Information managed by us or a vendor could significantly impact our business through diminished market perception of the effectiveness of our security measures, legal or regulatory actions, substantial fines, penalties and required changes to our business practices, damage to our reputation or our business, loss of existing customers and our ability to obtain new customers (including government customers), significant restoration, remediation and compliance costs, and cause harm to our financial condition. Any or all of the foregoing could materially adversely affect our business, financial condition and results of operations. Also, we cannot guarantee that any costs and liabilities incurred in relation to an attack or incident will be covered by our existing insurance policies or that applicable insurance will be available to us in the future on economically reasonable terms or at all.
39