Skip to content
KStart free
AI InfrastructureDefenseQuantumAll studies →

PAYC US Equity

Paycom Software, Inc.Information Technology · Services-Prepackaged Software · CIK 1590955 · FY ends Dec 31
$229.07
+2.35 (+1.04%)
USD · as of 2026-08-21 · marketstack

PAYC · 10-K · period ended 2025-12-31

← all PAYC documents
filed 2026-02-19 · EDGAR original ↗

Our rendering of the filing — original pagination and typography are not reproduced, and tables are reduced to their short label cells (the figures live on FA). Nothing is summarized: every line below is the filing's own text.

blocks 1587 of 1,520320k characters rendered

10-K

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION

Washington, D.C. 20549

FORM 10-K

(Mark One)

For the fiscal year ended December 31, 2025

or

For the transition period from ______ to ______

Commission File Number: 001-36393

Paycom Software, Inc.

(Exact name of registrant as specified in its charter)

Registrant’s telephone number, including area code: (405) 722-6900

Securities registered pursuant to Section 12(b) of the Act:

Title of each class Trading Symbol(s) Name of each exchange on which registered

Common Stock, $0.01 par value PAYC New York Stock Exchange

Securities registered pursuant to Section 12(g) of the Act: None

Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes ☒ No ☐

Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐ No ☒

Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes ☒ No ☐

Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes ☒ No ☐

Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.

Large accelerated filer ☒ Accelerated filer ☐

Non-accelerated filer ☐ Smaller reporting company ☐

Emerging growth company ☐

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐

Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒

If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. ☐

Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☐

Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Act). Yes ☐ No ☒

As ofFebruary 10, 2026, 54,275,097 shares of the registrant’s common stock, $0.01 par value per share, were outstanding, including 1,114,039 shares of restricted stock. As of June 30, 2025, the aggregate market value of voting stock held by non-affiliates of the registrant was approximately $11.9 billion (based on the closing price for shares of the registrant’s common stock as reported by the New York Stock Exchange on that date).

DOCUMENTS INCORPORATED BY REFERENCE

Portions of the registrant’s Definitive Proxy Statement on Schedule 14A to be furnished to stockholders in connection with its 2026 Annual Meeting of Stockholders are incorporated by reference in Part III, Items 10-14 of this Annual Report on Form 10-K.

PAYCOM SOFTWARE, INC.

2025 ANNUAL REPORT ON FORM 10-K

TABLE OF CONTENTS

PART I

Item 1. Business 6

Item 1A. Risk Factors 19

Item 1B. Unresolved Staff Comments 34

Item 1C. Cybersecurity 35

Item 2. Properties 37

Item 3. Legal Proceedings 37

Item 4. Mine Safety Disclosures 38

PART II

Item 6. Reserved 40

Item 7A. Quantitative and Qualitative Disclosures About Market Risk 52

Item 8. Financial Statements and Supplementary Data 54

Item 9A. Controls and Procedures 81

Item 9B. Other Information 81

Item 9C. Disclosure Regarding Foreign Jurisdictions that Prevent Inspections 81

PART III

Item 10. Directors, Executive Officers and Corporate Governance 83

Item 11. Executive Compensation 83

Item 14. Principal Accounting Fees and Services 83

Item 15. Exhibits, Financial Statement Schedules 84

Signatures 88

3

Unless we state otherwise or the context otherwise requires, the terms “Paycom,” “we,” “us,” “our” and the “Company” refer to Paycom Software, Inc., a Delaware corporation, and its consolidated subsidiaries.

CAUTIONARY STATEMENTS

Special Note Regarding Forward-Looking Statements

This Annual Report on Form 10-K (this “Form 10-K”) contains forward-looking statements within the meaning of Section 27A of the Securities Act of 1933, as amended (the “Securities Act”) and Section 21E of the Securities Exchange Act of 1934, as amended (the “Exchange Act”). Forward-looking statements are any statements that refer to our estimated or anticipated results, other non-historical facts or future events and include, but are not limited to, statements regarding our business strategy; anticipated future operating results and operating expenses, cash flows, capital resources, dividends and liquidity; competition; trends, opportunities and risks affecting our business, industry and financial results, including macroeconomic factors; future expansion or growth plans and potential for future growth, including internationally; our ability to attract new clients to purchase our solution; our ability to retain clients and induce them to purchase additional applications; our ability to accurately forecast future revenues and appropriately plan our expenses; market acceptance of our solution and applications; our expectations regarding future revenues generated by certain applications; the return on investment for users of our solution, as well as how certain applications may impact client employee usage and client satisfaction; our ability to attract and retain qualified employees and key personnel; future regulatory, judicial and legislative changes; how the performance of certain of our offerings is sensitive to changes in the labor market; our plan to open additional sales offices and our ability to effectively execute such plan; the sufficiency of our existing cash and cash equivalents to meet our working capital and capital expenditure needs over the next 12 months; our plans regarding our capital expenditures and investment activity as our business grows, including with respect to research and development and the expansion of our facilities; our plans to pay cash dividends; and our plans to repurchase shares of our common stock through a stock repurchase plan using cash and/or borrowings under our senior secured revolving credit facility (the “Revolving Credit Facility”). In addition, forward-looking statements also consist of statements involving trend analyses and statements including such words as “anticipate,” “believe,” “could,” “estimate,” “expect,” “intend,” “may,” “might,” “plan,” “potential,” “should,” “will,” “would,” and similar expressions or the negative of such terms or other comparable terminology.

Forward-looking statements are neither historical facts nor assurances of future performance, and are based only on our current beliefs, expectations and assumptions regarding the future of our business, future plans and strategies, projections, anticipated events and trends, the economy and other future conditions. Because forward-looking statements relate to the future, they are subject to inherent uncertainties, risks and changes in circumstances that are difficult to predict and many of which are outside of our control. Therefore, you should not rely on any of these forward-looking statements. Important factors that could cause our actual results and financial condition to differ materially from those indicated in the forward-looking statements include, among others, the following:

the possibility of security vulnerabilities, cyber-attacks and network disruptions, including breaches of data security and privacy leaks, data loss, and business interruptions;

changes in laws, government regulations and policies and interpretations thereof;

our compliance with data privacy laws and regulations;

our ability to develop enhancements and new applications, keep pace with technological developments and respond to future disruptive technologies, such as artificial intelligence (“AI”) and machine learning technologies;

our ability to compete effectively in an evolving human capital management (“HCM”) industry;

our ability to maintain and expand existing client relationships and add new clients, including challenges related to attracting and retaining larger clients;

the possibility that our solution fails to perform properly or our clients are not satisfied with our services;

our dependence on our key executives;

our ability to attract and retain qualified personnel;

our ability to manage our growth and organizational change effectively;

our ability to manage risks associated with our automation strategy;

the impact of adverse economic and market conditions, including those related to fluctuations in interest rates, trade policies, labor trends, global health crises and geopolitical conflicts;

fluctuations in our financial results due to factors beyond our control;

our failure to develop and maintain our brand cost-effectively;

our ability to expand into international markets and manage risks associated with international operations and sales;

4

our reliance on relationships with third parties;

regulatory and compliance risks related to our background checks business;

our failure to adequately protect our intellectual property rights;

seasonality of certain operating results and financial metrics; and

the other factors set forth in Part I, Item 1A, “Risk Factors” of this Form 10-K.

Forward-looking statements are based only on information currently available to us and speak only as of the date of this Form 10-K. We do not undertake any obligation to update or revise the forward-looking statements to reflect events that occur or circumstances that exist after the date on which such statements were made, except to the extent required by law.

Additional Information

The Vault Visa® Payroll Card is issued by The Bancorp Bank, N.A., Member FDIC, pursuant to a license from Visa U.S.A Inc. and may be used everywhere Visa debit cards are accepted.

“Paycom,” the Paycom logo and other trademarks or service marks of Paycom appearing in this Form 10-K are the property of Paycom and are protected under applicable intellectual property laws. Google and Google Pay are registered trademarks of Google, LLC. Apple and Apple Pay are trademarks of Apple, Inc., registered in the United States and other countries. Samsung and Samsung Pay are trademarks owned by Samsung Electronics Co., Ltd. Visa is a registered trademark of Visa International Service Association. All other marks are the property of the respective owners of such marks. Solely for convenience, our trademarks and tradenames referred to in this Form 10-K may appear without the ® or TM symbols, but such references are not intended to indicate in any way that we will not assert, to the fullest extent under applicable law, our rights to these trademarks and tradenames.

5

PART I

Item 1. Business

Overview

We are a leading provider of a comprehensive, cloud-based HCM solution delivered as Software-as-a-Service (“SaaS”). We provide functionality and data analytics that businesses need to manage the complete employment lifecycle, from recruitment to retirement. Our solution requires virtually no customization and is based on a core system of record maintained in a single database for all HCM functions, including payroll, talent acquisition, talent management, human resources (“HR”) management and time and labor management applications. Our user-friendly software allows for easy adoption of our solution by employees, enabling self-management of their HCM activities in the cloud, which reduces the administrative burden on employers and increases employee productivity.

We were founded in 1998 and became a publicly traded company through our initial public offering in 2014. Since our founding, we have focused on providing an innovative SaaS HCM solution. Organizations need sophisticated, flexible and intuitive applications that can quickly adapt to their evolving HCM requirements, streamline their HR processes and systems and enable them to control costs. We believe the HCM needs of many organizations are currently served by multiple providers, which often results in challenges with system integration and data integrity, low scalability, high costs and extended delivery times.

Because our solution was developed in-house and is based on a single platform, there is no need for our clients to integrate, update or access multiple databases, which are common issues with competitor offerings that use multiple third-party systems in order to link together their HCM offerings. Our solution allows clients to automate decisions and time-consuming HR and payroll tasks, freeing them up to focus on strategic items such as employee engagement and workforce planning. Additionally, our solution maintains data integrity for accurate, actionable and real-time analytics and business intelligence and helps clients minimize the risks of compliance errors due to inaccurate or missing information. We deliver feature-rich applications while maintaining excellence in information security, data privacy, business continuity, and quality management standards, as evidenced by our International Organization for Standardization (“ISO”) certifications.

We sell our solution directly through our internally trained, client-focused and highly skilled sales force based in offices across the United States. As a part of our client retention effort, a specialist within a dedicated team is assigned to each client to provide differentiated, personalized service. We have approximately 39,200 clients. We believe that as a result of our focus on client experience, we enjoy high client satisfaction as evidenced by an annual revenue retention rate of 91% and 90% for the years ended December 31, 2025 and 2024, respectively. We believe our revenue retention rate understates our client loyalty because this rate is negatively impacted when former clients are acquired or otherwise cease operations.

We have historically generated the majority of our revenues from our payroll applications. We generally do not separately track our revenues across our other applications because we often sell applications in various groupings and configurations for a single price.

The Paycom Solution

We offer an end-to-end SaaS HCM solution that provides our clients and their employees with immediate access to accurate and secure information and analytics at any time from any location where internet service is available. We believe our solution delivers the following benefits:

Comprehensive HCM Solution

Our solution offers functionality that manages the entire employment lifecycle for employers and employees, from recruitment to retirement. Our user-friendly applications streamline client processes and provide clients and their employees with the ability to directly access and manage administrative processes, including applications that identify candidates, on-board employees, manage time and labor, administer payroll deductions and benefits, manage performance, terminate employees and administer post-termination health benefits such as COBRA. Our solution allows clients to automate numerous decisions and tasks from onboarding to offboarding, including payroll, position changes and other processes. The widespread employee usage of our applications further integrates our solution into the administrative processes of our clients. Our solution also has the advantage of being built in-house by our highly trained and skilled team of software developers, thereby minimizing data integrity issues across applications.

Core System of Record

Our solution is based on a core system of record that contains payroll and HR information in one convenient database, thereby reducing costs and eliminating the need for multiple software products and vendors and the maintenance of employee data in numerous databases. This core system of record enables our clients to input employee data one time and enjoy seamless functionality across our applications. When a revision is made to the file of an employee, all appropriate personnel have access to the change in real time. In addition, our core system of record helps clients minimize the risk of compliance errors due to inaccurate or missing information that results from maintaining multiple databases. Through accurate tracking and management

6

of employee payroll and other HR data, such information can be compiled for comprehensive and consistent reporting for our clients.

Data Analytics and Business Intelligence

Our solution’s core system of record allows clients to strategically analyze comprehensive and accurate employee information to make informed business decisions based upon actionable, real-time analytics provided through our client dashboard. This functionality allows our clients to operate with a more complete and accurate picture of their organization, as our solution’s embedded analytics capture the content and context of everyday business events, facilitating fast and informed decision-making from any location. Our industry-first employee usage management analytics tool, Direct Data Exchange® (DDX®), provides employers insights into efficiencies gained through employee usage of HR technology and generates a real-time estimate of the savings realized from that usage. We help clients reduce administrative and operational costs and better manage talent through automated processes.

Enhanced Employee Experience

The employees of our clients also benefit from our HCM applications. As workforces transition from technology-savvy to technology-dependent, employees expect mobile technology and the resources necessary to readily access information and control their professional development. Through our employee self-service technology, employees can view real-time HR information, including pay stubs, payroll tax filing forms and benefits information, as well as manage their schedules and vacation time and update contact information. Our industry-first AI engine, IWantTM, provides instant and accurate access to employee data without requiring the user to navigate or learn our software. Employees can even do their own payroll with our first-of-its-kind Beti® technology. Our mobile app makes it easier for employees to access their self-service information. Our app has fingerprint and facial recognition capabilities, aiding employers in their efforts to engage technology-dependent workers. Our system also allows employers to engage their workforce through learning management courses and training paths, surveys, and performance goals and reviews.

To further enhance the effectiveness of management throughout our clients’ organizations, we also offer easy to use software with Manager on-the-Go®. Built within our mobile app, this tool allows for 24/7 accessibility to essential manager-side functionality, giving supervisors and managers the ability to perform a variety of tasks — anytime, anywhere.

In addition to our self-service, app-based functionality, we also provide our clients with a strategy to drive usage among their employees. This strategy includes training clients’ employees how to use the Paycom app during implementation and providing additional training from our client relations representatives (“CRRs”). Allowing employees to make changes directly to our database creates efficiencies for both the employer and employee. Today’s employees have little tolerance for complexity, and with our solution, employees have become accustomed to having a direct relationship with their HR data. This relationship is directly correlated with our single-database that is key to increasing usage and providing an employee-first experience. For example, IWant provides employees access to their HR data easily through voice-to-text functionality or typing a question, and our AI engine immediately provides the answer or directs users to the appropriate location to interact with their information. Our strategy to promote employee usage of the Paycom system elevates HR personnel to focus on the human element of their jobs, creating a more positive culture and giving HR personnel more time to engage with their employees.

Personalized Support Provided by Trained Personnel

Our applications are supported by one-on-one personal assistance from trained specialists. Service specialists are assigned to specific clients and are trained across all of our applications, ensuring they provide comprehensive, expert-level service. Our Quality Management System is ISO 9001:2015 certified on the basis of its quality and consistency. We strive to provide our clients with high levels of service and support to ensure their continued use of our solution for all of their HCM needs.

Software-as-a-Service Delivery Model

Our SaaS delivery model allows clients with geographically dispersed and mobile workforces to operate more efficiently, and allows these clients to implement, access and use our client-oriented internet solution on demand and remotely through standard web browsers, smart phones, tablets and other web-enabled devices. Our SaaS solution reduces the time, risk, headcount and costs associated with installing and maintaining applications for on-premises products within the information technology (“IT”) infrastructure of our clients.

Secure Cloud-Based Architecture

Our cloud-based architecture allows our solution to be implemented remotely with minimal client interaction. Updates such as software enhancements and newly developed applications can be deployed without client interaction, disruption or involvement, allowing our clients to make a smaller investment in hardware, personnel, implementation time and consulting. Additionally, we own and maintain all of the infrastructure technology to host our solution and to maximize system availability for clients. Our focus on, and investment in, technology, data security, and resiliency has been recognized with ISO/IEC 22301:2019, ISO/IEC 27001:2022, ISO/IEC 27701:2019, and ISO/IEC 42001:2023 certified security and business continuity standards.

7

Scalability to Grow with our Clients

Our solution is highly scalable. Our target client size is organizations with 50 to 10,000 or more employees. Our clients are able to use the same solution while their businesses grow by deploying applications as needed in real-time. Pricing is determined based on employee headcount and the number of applications utilized, enabling our clients to align HCM spending with their evolving HCM needs.

Efficient and Productive Research and Development

We believe we benefit from a competitive advantage with our research and development investments, people and processes. Early investments in our proprietary, cloud-based architecture enable us to develop and deploy applications in a timely and cost-effective manner. We have also chosen to base our research and development team in Oklahoma and Texas, which we believe provides us with high-quality talent at a lower cost compared to other locations in the United States where there is more competition for technology talent. These strategic decisions have enabled us to have a highly productive research and development function.

Our Strategy for Growth

Our strategy is to continue to establish our solution as the HCM industry standard by continuing to leverage our sales force productivity, penetrating existing markets and expanding into new markets. We intend to continue to increase our domestic sales capacity and expand our offering to additional international markets. We will also execute our strategy for growth by targeting large clients and strengthening and extending our solution.

Penetrate Existing Markets

We believe a significant market opportunity exists to penetrate markets where we currently have existing sales offices. Each sales office is typically staffed with one outside sales team, consisting of a sales manager and six to 10 other sales professionals. We plan to penetrate and more effectively capture existing markets through increased sales productivity as well as by adding sales capacity in such markets. Although we have a sales office in 41 of the 50 largest metropolitan statistical areas (“MSAs”) in the United States based on July 2024 U.S. Census Bureau estimates, only seven of these MSAs are currently served by multiple Paycom outside sales teams.

Enlarge our Existing Client Relationships

We dedicate our resources to helping our clients facilitate their goals, whether through helping our clients execute better hiring decisions, manage compensation more effectively or simply operate more efficiently. We believe a significant growth opportunity exists in selling additional applications to our current clients. Many clients have subsequently deployed additional applications as they recognize the benefits of our comprehensive solution. Furthermore, with the launch of our Global HCMTM solution and expansion of payroll services into certain international markets, we have the opportunity to capture additional revenue from existing clients with international employees. As we extend and enhance the functionality of our solution, we will continue to invest in initiatives to increase the adoption of our solution and maintain our high levels of client satisfaction.

Expand Into New Markets

We plan to continue expanding our sales capability by opening sales offices in certain metropolitan areas where we currently have no sales teams. We have historically selected new locations based on potential client and employee demographics as well as business density. When opening a new sales office, we typically relocate a proven sales manager from an existing territory who then recruits a team of high-performing sales representatives. It typically takes a new sales office 24 months to reach maturity. In addition, as we continue to enhance the global capabilities of our solution, our U.S.-based sales teams are expanding our reach into international markets by targeting global organizations with a U.S. presence.

Target Large Clients

The average size of our clients has grown significantly as we have organically grown our operations and increased the number of applications we offer. We believe larger employers, such as organizations with greater than 1,000 employees, represent a substantial opportunity to increase our revenues per client, with limited incremental cost to us, and we intend to continue targeting large businesses. In addition, we expect that our ability to serve organizations with international employees makes our solution more attractive to larger companies, many of which have a global presence.

Maintain Our Leadership in Innovation by Strengthening and Extending our Solution

Our ability to develop and deploy new applications and updates rapidly and cost-effectively has been integral to the results that we have achieved to date. We intend to continue extending the functionality and range of our solution in the future, and we are incorporating and leveraging AI and automation across our full solution. Our development efforts are performed exclusively in-house and are heavily based upon proactive research and client input. We are focusing our investments on the development of new applications, enhancements and learning courses that are responsive to the needs of our clients, which are garnered through ongoing client interaction and collaboration.

8

Our Applications and Tools

Our HCM solution offers a full suite of applications and tools that generally fall within the following categories: payroll, talent acquisition, talent management, HR management and time and labor management. Enhancing the value of our comprehensive product suite is IWant, our industry-first command driven AI engine empowering users to navigate and access their information within our single database.

With Global HCM, a number of our HCM applications and tools are available in 15 languages and dialects and are accessible to users in more than 190 countries. We also offer native payroll in Canada, Mexico, the United Kingdom and Ireland, and intend to add native payroll in other countries.

Payroll

9

Talent Acquisition

Talent Management

10

HR Management

11

12

Time and Labor Management

Our Clients

We serve a diverse payroll and HCM client base in terms of size and industry. We have approximately 39,200 clients, or approximately 20,300 clients based on parent company grouping. We stored data for over 7.4 million persons employed by our clients during the year ended December 31, 2025.

Many small to mid-sized companies can typically make the decision to adopt our solution more quickly than larger companies, which we believe results in a shorter sales cycle and more closely corresponds to our target sales cycle of 30 to 90 days. As a result of the nature and size of our clientele, we maintain a diversified client base and very low revenue concentration among our clients. We believe, however, that larger employers represent a substantial opportunity to increase our revenues per client with limited incremental cost. As we pursue and attract larger clients, we may face longer sales cycles and less predictability in completing some of our sales.

13

Competition

The market for HCM solutions is rapidly evolving, highly competitive and subject to changing technology, shifting client needs and frequent introduction of new products and services. Our competitors range from small, regional firms to large, well-established international firms with multiple product offerings.

Our competitors offer HCM solutions that may overlap with one, several or all categories of the applications we offer. We compete with companies such as Automatic Data Processing, Inc., Dayforce, Inc., Intuit, Inc., Oracle Corporation, Paychex, Inc., Paylocity Holding Corporation, SAP SE, ServiceNow, Inc., Ultimate Kronos Group, Workday, Inc., and other international, national, regional, and local providers. Our competitors provide HCM solutions by various means. Although certain providers continue to deliver legacy enterprise software, most now offer cloud-based solutions, resulting in increased competition for clients seeking the greater flexibility and access to information provided by cloud-based offerings. Furthermore, the HCM industry has experienced an emergence of white label and embedded payroll offerings.

Competition in the HCM solutions market is primarily based on service responsiveness, product quality and reputation, breadth of service, application offering and price. The importance of these factors depends on the size of the business. Price tends to be the most important factor of competition for smaller businesses with fewer employees, while the scope of features and customization is more important to larger businesses. Regardless of a company’s size, another important factor is the implementation experience, as all organizations are seeking a streamlined and simplified process.

Sales and Marketing

We generate client leads and demo requests, accelerate sales opportunities and build brand awareness through our marketing programs that target senior finance and HR executives, technology professionals and senior business leaders of companies that perform HCM functions in-house or outsource these functions to one of our competitors. Our marketing programs include:

Podcasts, webinars, blogs, white papers and infographics;

National and local television advertising campaigns, personalized direct mail campaigns, email campaigns, social and digital media campaigns, industry-specific advertising and tradeshow exhibiting; and

Search engine marketing methods that include site optimization and pay-per-click searches.

We sell our solution exclusively through our captive sales force, substantially all of whom have a four-year college degree. We typically recruit sales candidates who have sales experience in non-HCM industries or, with respect to candidates recruited directly from colleges and universities, who have demonstrated an aptitude for sales. Our sales force is comprised of field sales personnel, who are organized geographically, CRRs, who sell additional applications to existing clients, and our emerging markets representatives, who focus on businesses with fewer than 65 employees. As of the filing of this Form 10-K, we have 58 sales teams (with CRRs and emerging markets representatives counted as one team) located in 29 states and plan to open additional sales offices to further expand our market presence.

When a new client processes payroll with us for an entire month, our sales representative receives a one-time commission based upon an estimate of future annual revenues from such client. Executive sales representatives receive a higher commission rate and base salary based upon both current year and career-to-date realized sales.

In addition to managing client relationships, our CRRs are focused on expanding the number of applications our clients purchase from us by introducing them to additional applications. When an existing client purchases and then utilizes a new application, a CRR receives a one-time commission based upon an estimate of future annual revenues from such client.

Technology, Operations and Security

Technology

Our multi-tenant architecture enables us to deliver our solution across our client base from a single platform, while securely partitioning access to our clients’ respective application data. Because a single version of our solution is developed, supported and deployed across all of our clients, the Paycom solution is seamlessly scalable.

Operations

We physically host our solution for our clients in secure data center facilities located in Oklahoma, Texas, and Arizona. Each of these data centers is managed by Paycom, and Paycom is the only tenant occupying the data centers. All of our critical systems are fully redundant and backed up at regular intervals to these facilities, and backups are monitored for success and failure status daily. Client data is backed up in real-time among the data centers. We maintain redundant load-balanced internet lines serviced by multiple service providers to each data center, to ensure optimized client access to our solution and the clients’ stored data. Our server and database clusters are fully redundant to ensure continuous service in the event of a disk failure.

Physical security includes biometric and dedicated ID-oriented access control, redundant alarm systems and continuous camera monitoring by our security guards. The data centers also have environmental monitoring and extensive environmental

14

controls such as heat and fire protection, moisture, temperature, and humidity sensors, backup power supply and exterior reinforced concrete walls.

Security

We maintain a formal and comprehensive security program designed to ensure the confidentiality, integrity and availability of our clients’ data. For a discussion of our information security program, see “Item 1C. Cybersecurity.”

Software Development

We develop our solutions from the “ground up” with our internal development and engineering teams. We also work closely with our clients to enhance our existing application offerings and develop new applications. Our teams conceive new applications and enhancements, review requests, schedule development in order of priority and subsequently develop the applications or enhancements. New applications and enhancements are independently reviewed by the quality assurance team, in accordance with our software development process, before being fully implemented. Enhancements to our applications are typically released on a monthly scheduled release date to coordinate the communication and release to our clients.

Client Service

We are committed to providing industry-leading, client-centered service. For this reason, we assign each client a specialist within a dedicated team. This one-on-one service is a key part of our client service model and helps to ensure we are delivering a differentiated solution and maintaining high client satisfaction. The primary elements of our client service model include the following:

Streamlined Setup and Onboarding

After electing to deploy our solution, a new client begins our onboarding process with assistance from a team of new client setup specialists and the sales representative responsible for obtaining the client’s business. In addition, we also have a team of transition specialists whose job it is to ensure that the process is performed smoothly, data is collected properly and all relevant employees are fully trained on the system. This team works closely with the client until the client is capable of managing our solution independently, at which time responsibility for the client relationship is transferred to our dedicated CRRs and service specialists. Unlike certain of our competitors, we do not outsource any of our onboarding efforts.

Dedicated Service Specialists

After completing the onboarding process, each client is assigned to a service specialist within a dedicated team. Clients can then contact their dedicated service specialist or a team member if any issues or questions arise. These specialists provide personalized service with a historical knowledge of the clients’ communicated business needs. In addition, our CRRs proactively contact our clients to ensure satisfaction with our solution and introduce additional applications.

Expert Level Service

Our service specialists are trained across all of our applications to ensure that they can provide comprehensive, expert-level service. Our Quality Management System is ISO 9001:2015 certified and helps support our high client retention rate.

Government Regulation

We are subject to various regulations in each of the jurisdictions in which we provide services. Local laws and regulations, and their interpretation and enforcement, differ significantly among those jurisdictions. We are also subject to certain federal, state, local and foreign regulations based on the products we offer. For example, as a result of our background screening application, Enhanced Background Checks, we are subject to the Fair Credit Reporting Act and other federal and state background reporting laws. Further, our status as a government contractor subjects us to federal government contracting regulations including the adherence to heightened equal employment opportunity requirements, maintaining an affirmative action plan and other federal regulations.

Data privacy has become a significant issue in the United States and in other countries. The regulatory framework for privacy issues worldwide is rapidly evolving and is likely to remain uncertain for the foreseeable future. Many federal, state and foreign government bodies and agencies have adopted or are considering adopting laws and regulations affecting or regarding the collection, use and disclosure of personal information. In the United States, these include, for example, rules and regulations promulgated under the authority of the Federal Trade Commission, the Health Insurance Portability and Accountability Act of 1996, the Family Medical Leave Act of 1993, the ACA, the Financial Services Modernization Act of 1999, the Gramm-Leach-Bliley Act, state biometric privacy laws, including the Illinois Biometric Information Privacy Act (“IBIPA”), state breach notification laws and state consumer privacy laws, including the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”). Numerous other states have now enacted their own consumer data privacy statutes, many of which are modeled on the CCPA, including states like Colorado, Connecticut, Delaware, Oregon, Montana, Nebraska, New Hampshire, New Jersey, Utah, Virginia, Iowa, and Tennessee. Further, because some of our clients have international establishments, the Canadian Personal Information Protection and Electronic Documents Act (“PIPEDA”),

15

Mexico’s Federal Law on the Protection of Personal Data held by Private Parties, and the European Union’s General Data Protection Regulation (“EU GDPR”) and other foreign data privacy laws may impact our processing of certain client and employee information.

Furthermore, AI and machine learning software tools have continued to evolve and improve, and these tools have become increasing vital to the development and support of our applications and services. Legislative authorities in the United States and the European Union have responded to this evolution by enacting and/or proposing legislation that imposes restrictions on the development, use, and training of generative AI models and algorithms. On May 21, 2024, the European Union legislators approved the EU Artificial Intelligence Act (the “EU AI Act”), which establishes a comprehensive, risk-based governance framework for AI in the EU market. The EU AI Act went into effect on August 2, 2024, and the majority of the substantive requirements will go into effect on August 2, 2026. The EU AI Act, and developing interpretation and application of the GDPR in respect of automated decision making, together with developing guidance and/or decisions in this area, may affect our use of AI technologies and our ability to provide, improve or commercialize our business, require additional compliance measures and changes to our operations and processes and result in increased compliance costs and potential increases in civil claims against us. The regulatory landscape related to generative AI and machine learning is rapidly evolving and is likely to remain uncertain for the foreseeable future. As we continue to develop and improve our services by incorporating technologies such as generative AI and machine learning, we must monitor and comply with these new applicable AI laws and regulations.

Anti-corruption, anti-money laundering (“AML”), and economic and trade sanctions laws and regulations are under continuously expanding scrutiny by regulators worldwide. We are subject to trade and economic sanctions programming, including schedules administered by the U.S. Treasury Department Office of Foreign Assets Control, which prohibit us from engaging in transactions or dealings with blocked countries, their governments, and, occasionally, specified nationals, including specially designated individuals and entities.

Globally, we intend to maintain registrations and licenses in regulatory alignment with the countries in which we operate. We are registered with the U.S. Treasury Department Financial Crimes Enforcement Network, and Paycom Canada, Inc. is a registered Money Service Business with the Financial Transactions and Reports Analysis Centre of Canada. In 2024, the Office of the Comptroller of Currency (the “OCC”) authorized us to open the Paycom National Trust Bank, National Association (the “Paycom National Trust Bank”), via a national trust bank charter pursuant to the National Bank Act. The Paycom National Trust Bank is the sole trustee of Paycom Client Trust, our grantor trust, which now holds substantially all client payroll and related funds and is responsible for the oversight and management of those client funds. The Paycom National Trust Bank and all its fiduciary activities, including the U.S. money movement it oversees and manages via Paycom Client Trust, are subject to comprehensive ongoing oversight and regulation by the OCC. In addition, our U.S. money movement managed by the Paycom National Trust Bank is subject to the AML and reporting provisions of The Bank Secrecy Act of 1970, as amended by the USA Patriot Act of 2000 (the “BSA”). Our money movement activities outside of the United States are subject to similar licensing and AML and reporting laws and requirements in the countries in which we provide such services.

Certifications

We voluntarily obtain third-party security examinations relating to our internal controls over financial reporting in accordance with System and Organization Controls Report, I (“SOC 1”). Our SOC 1 examination is conducted every six months by an independent international auditing firm, and addresses, among other areas, our physical and environmental safeguards for production data centers, data availability and integrity procedures, change management procedures and logical security procedures. We also obtain third-party examinations relating to our internal controls over security and privacy in accordance with System and Organization Controls Report, II (“SOC 2”). Our SOC 2 examination is conducted every year and addresses, among other areas, internal controls around security, availability, and processing integrity. We publish SOC 1 reports semiannually and SOC 2 and SOC 3 reports annually.

We maintain a certification based on ISO 9001:2015 criteria, a standard for the implementation of a Quality Management System published by ISO, covering our activities required to create and deliver our solution. This independent assessment of our conformity to the ISO 9001:2015 standard includes assessing the design and implementation of quality objectives to meet delivery standards on an ongoing basis. The certification is valid until April 2026, with continuing assessments taking place annually.

We maintain a certification based on ISO 22301:2019 criteria, a standard for implementing and managing an effective Business Continuity Management System (BCMS) published by ISO. This international standard for continuity management specifies requirements to plan, implement, operate and continually improve a documented management system to protect against, prepare for, respond to and recover from disruptive incidents when they arise. The certification is valid until January 2029, with continuing assessments taking place annually.

We maintain a certification based on ISO/IEC 27001:2022 criteria, a security standard for Information Security Management Systems published by ISO covering our production, quality assurance and implementation environments. This independent assessment of our conformity to the ISO 27001 standard includes assessing security risks, designing and

16

implementing comprehensive security controls and adopting an information security management process to meet security needs on an ongoing basis. The certification is valid until February 2029, with continuing assessments taking place annually.

We maintain a certification based on ISO/IEC 27701:2019 criteria, a standard for establishing, implementing, maintaining and continually improving a Privacy Information Management System (“PIMS”) published by ISO. This international standard for PIMS specifies PIMS-related requirements and provides guidance for Personally Identifiable Information (“PII”) controllers and PII processors holding responsibility and accountability for PII processing. The certification is valid until February 2029, with continuing assessments taking place annually.

In November 2025, we obtained a certification based on ISO/IEC 42001:2023 criteria, a standard for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System (“AIMS”) published by ISO. This international standard for AIMS specifies AIMS-related requirements and provides guidance for ensuring responsible development and use of AI systems. The certification is valid until November 2028, with continuing assessments taking place annually.

Intellectual Property

We rely on a combination of copyrights, trademarks, service marks, trade secrets and contractual restrictions to establish and protect our intellectual property rights. We have a number of registered and unregistered trademarks designed to protect our brand and goodwill, and we will continue to evaluate the registration of additional trademarks as appropriate. We do not have any patents or patent applications pending.

Seasonality

Our revenues are seasonal in nature. Generally, we expect our first and fourth quarter revenues to be higher than other quarters during the year because payroll tax filing forms and ACA forms are typically processed in the first quarter, and unscheduled payroll runs (such as bonuses) for our clients are typically concentrated in the fourth quarter. We anticipate that our revenues will continue to exhibit this seasonal pattern related to ACA form filings for so long as the ACA (or replacement legislation) includes employer reporting requirements. Nonetheless, we expect the magnitude of these seasonal fluctuations in our revenues to decrease to the extent clients utilize more of our non-payroll applications.

Human Capital

As of December 31, 2025, we employed 5,770 people, substantially all of whom are full-time employees. Our human capital objectives include attracting, developing and retaining the best talent in the industry. We have been recognized nationally for providing our employees with an excellent work environment. We strive to foster an inclusive workplace that is free from harassment or discrimination, including harassment or discrimination involving race, color, sex, religion, gender, age, national origin, disability, gender identity or expression, sexual orientation, veteran or marital status.

Culture and Values

Paycom’s purpose is to create technology that simplifies life for employees. Our purpose guides every aspect of our business and creates a culture that aligns our employees with the core values of our company:

We Innovate

We Win

We Care

We Serve

We Believe

These values further define us and drive our success. They steer how we work with our clients and each other. Paycom would not be the company it is today without a deep desire to win and innovate new ideas. Our focus on people — including our team members, our clients and their employees — and caring about their experience, health and success, is at the heart of our culture. Our can-do attitude helps us embrace uncertainty with optimism and believe we can achieve what others consider impossible.

17

Workforce Demographics

We recognize Paycom plays an important part in the lives of our employees and strive to create an inclusive workplace where employees feel heard, valued and appreciated for who they are. We continue to work toward our goal of attracting, retaining and developing a workforce that is diverse in background, knowledge, skill and experience at all employee levels, from entry level to executive. The demographic workforce data within the table below, including race and ethnicity, gender and job categories, aligns with the EEO-1 Component 1 data collection reporting requirements outlined by the U.S. Equal Employment Opportunity Commission, where applicable, and includes U.S.-based employees only.

Gender:

Race and Ethnicity:

American Indian or Alaskan Native 1.9 % 2.4 % —

Black or African American 7.1 % 5.0 % —

Hispanic or Latino 10.7 % 7.3 % 1.7 %

Native Hawaiian or Pacific Islander 0.4 % — —

Two or more races 4.4 % 3.1 % —

Not Specified 0.5 % — —

Training and Development

Through the use of our Paycom learning tool, we empower our employees by providing tailored learning paths in areas such as leadership, inclusion, technical skills and compliance.

We provide our sales force with intensive training courses. Our unique training program includes instruction in accounting, business metrics, application features and tax matters relevant to our target market, and we believe it fosters loyalty and helps maintain our corporate culture. Our training continues for our sales force through weekly strategy sessions and leadership development training. All sales representatives and leaders attend in-person training several times throughout the year to stay up to date on our products and the competitive landscape, as well as to receive compliance and business updates.

Health, Safety and Wellness

We believe that our employees are the summation of our successes, which is why we offer an excellent health and benefits program to our employees and their families. We offer our employees comprehensive health insurance as well as optional dental and vision coverage. Additionally, we provide our employees several opportunities to focus on physical, mental and financial wellness by maintaining a fully equipped on-site gym, 401(k) matching, an employee stock purchase plan, and paid vacation, holiday, family leave and sick leave, with numerous other benefits offered to our employees.

Segment Information

We operate in a single operating segment and a single reporting segment. Operating segments are defined as components of an enterprise about which separate financial information is regularly evaluated by the chief operating decision maker function (which is fulfilled by our Chief Executive Officer) in deciding how to allocate resources and in assessing performance. Our Chief Executive Officer allocates resources and assesses performance based upon financial information at the consolidated level. See Note 14 “Segment Reporting” in the notes to the consolidated financial statements for additional information.

Available Information

Our internet address is www.paycom.com, and our investor relations website is located at investors.paycom.com. Our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K and amendments to those reports can be found on our investor relations website, free of charge, as soon as reasonably practicable after we electronically file such material with, or furnish it to, the Securities and Exchange Commission (the “SEC”). Information contained on our website is not incorporated by reference into this Form 10-K. The SEC maintains a public website, www.sec.gov, which includes information about and the filings of issuers that file electronically with the SEC.

18

Item 1A. Risk Factors

The risk factors noted in this section and other factors noted throughout this Form 10-K, including those risks identified in Part II, Item 7, “Management’s Discussion and Analysis of Financial Condition and Results of Operations,” describe examples of risks, uncertainties and events that may cause our actual results to differ materially from those contained in any forward-looking statement. If one or more of these risks or uncertainties materialize, or if underlying assumptions prove incorrect, actual outcomes may vary materially from those included in this Form 10-K.

Risks Related to Our Business

If our security measures are breached, or unauthorized access to sensitive data is otherwise obtained, our solution may not be perceived as being secure, clients may reduce the use of or stop using our solution, our ability to attract new clients may be harmed and we may incur significant liabilities.

Our solution involves the collection, storage and transmission of confidential and proprietary information belonging to our clients, their current, former and potential employees and, in certain cases, dependents and beneficiaries of clients’ current and former employees. This information includes personal identifying information, as well as financial and payroll data. HCM software is often targeted, and we have been targeted, in cyber-attacks, including computer viruses, phishing attacks, malicious software programs (including distributed denial of services (DDoS) attacks) and other information security breaches, which could result in unauthorized access to or release, gathering, monitoring, misuse, loss or destruction of our or our clients’ sensitive data or otherwise disrupt our or our clients’ business operations. The techniques used to obtain unauthorized access to information, disable or degrade service, or sabotage systems change frequently, and are increasingly more complex and sophisticated, including due to the use of AI. If threat actors are able to circumvent our security measures and we are unable to detect or contain such intrusion into our system, our or our clients’ sensitive data (including client employees’ personal data) may be compromised. Further, in order to provide our services, certain of our employees have access to sensitive information about our clients’ employees. While we conduct background checks of our employees and limit access to systems and data, it is possible that one or more of these individuals may circumvent these controls, resulting in a security breach.

In certain limited circumstances, we utilize relationships with third parties to aid in data management and transaction processing. Certain third parties with which we do business have been subject to cyber-attacks, one of which resulted in unauthorized access to data of certain Company clients and their employees as well as Company data and employee records. These third parties may be sources of cybersecurity or other technological risks in the future, including operational errors, design or manufacturing defects, system interruptions or breaches, unauthorized disclosure of confidential information and misuse of intellectual property. Even without a direct breach of our systems, cyber-attacks on such third-party vendors or on our clients could adversely impact our business and reputation.

Although we have security measures in place to protect client information and prevent data loss and other security breaches, these measures have been in the past and in the future may be breached as a result of third-party action, employee error, third-party or employee malfeasance or other events. In addition, new computing technologies, including quantum computing, new discoveries in the field of cryptography or other developments could result in a compromise or breach of the algorithms we or our authorized third parties use or have used to encrypt and protect data. Globally, cybersecurity attacks are increasing in number and the threat actors are increasingly organized and well financed, or at times supported by state actors. In addition, geopolitical tensions or conflicts may create a heightened risk of cybersecurity attacks. Because the techniques used to obtain unauthorized access to or to sabotage systems change frequently, we may not be able to anticipate these techniques and implement adequate preventative, responsive or protective measures. As these threats continue to evolve and increase, including due to the use of AI by us and third parties, we continue to invest significant resources, and may be required to invest significant additional resources, to modify and enhance our cybersecurity controls and to investigate and remediate any security vulnerabilities. Our ability to address data or cybersecurity incidents may also depend on the timing and nature of assistance that may be provided from relevant governmental or law enforcement agencies. While we currently maintain a cyber liability insurance policy, cyber liability insurance may be inadequate or may not be available in the future on acceptable terms, or at all. In addition, our cyber liability insurance policy may cover only a portion of losses incurred in investigating or remediating an incident, if at all, and may not cover all claims made against us. Undergoing a government investigation or defending a lawsuit, regardless of merit, could be costly and divert management’s attention from our business and operations.

Any actual or perceived breach of our security could damage our reputation, cause existing clients to discontinue the use of our solution, prevent us from attracting new clients, or subject us to third-party lawsuits, regulatory investigations and fines or other actions or liabilities, any of which could adversely affect our business, operating results or financial condition.

Any damage, failure or disruption of our network infrastructure or data centers could impair our ability to effectively provide our solution, harm our reputation and adversely affect our business.

Our network infrastructure is a critical part of our business operations. Our clients access our solution through standard web browsers, smart phones, tablets and other web-enabled devices and depend on us for fast and reliable access to our solution. We serve all of our clients from our fully redundant data centers located in Oklahoma, Texas and Arizona. Our network infrastructure and data centers are vulnerable to damage, failure and disruption.

19

In the future, we may experience issues with our computing and communications infrastructure or data centers caused by the following factors:

human error;

telecommunications failures or outages from third-party providers;

computer viruses or cyber-attacks;

break-ins or other security breaches;

acts of terrorism, sabotage, intentional acts of vandalism or other misconduct;

tornadoes, fires, earthquakes, hurricanes, floods and other natural disasters;

insufficient supply or loss of power; and

other unforeseen interruptions or damages.

If our network infrastructure or our clients’ ability to access our solution is interrupted, client and employee data from recent transactions may be permanently lost, and we could be exposed to significant claims by clients, particularly if the access interruption is associated with problems in the timely delivery of funds payable to employees or tax authorities. Further, any adverse changes in service levels at our data centers resulting from damage to or failure of our data centers could result in disruptions in our services. Any significant instances of system downtime or performance problems at our data centers could negatively affect our reputation and ability to attract new clients, prevent us from gaining new or additional business from our current clients, or cause our current clients to terminate their use of our solution, any of which would adversely impact our revenues. In addition, if our network infrastructure and data centers fail to support increased capacity due to growth in our business, our clients may experience interruptions in the availability of our solution. Such interruptions may reduce our revenues, cause us to issue refunds to clients or adversely affect our retention of existing clients, any of which could have a negative impact on our business, operating results or financial condition.

If we are not able to develop enhancements and new applications, keep pace with technological developments or respond to future disruptive technologies, we might not remain competitive and our business could be adversely affected.

Our continued success will depend on our ability to adapt and innovate. In order to attract new clients and increase revenues from existing clients, we need to enhance, add new features to and improve our existing applications and introduce new applications. The success of any enhancements or new features and applications depends on several factors, including timely completion and introduction and market acceptance. We may expend significant time and resources developing and pursuing sales of a particular enhancement or application that may not result in revenues in the anticipated time frame or at all, or may not result in revenue growth sufficient to offset increased expenses. Further, changing legal and regulatory requirements may delay the development or introduction of enhancements or new applications or render certain of our applications obsolete. If we are unable to successfully develop enhancements, new features or new applications to meet client needs, our business and operating results could be adversely affected.

In addition, because our applications are designed to operate on a variety of network, hardware and software platforms using internet tools and protocols, we must continuously modify and enhance our applications to keep pace with changes in internet-related hardware, software, communication, browser and database technologies. If we are unable to respond in a timely and cost-effective manner to these rapid technological developments, our current and future applications may become less marketable and less competitive or even obsolete.

Our success is also subject to the risk of future disruptive technologies, such as AI and machine learning. The failure to develop enhancements to our applications for, or that incorporate, technologies such as natural language processing, AI, and machine learning may impact our ability to increase the efficiency of and reduce costs associated with our clients’ operations. If new technologies emerge that are able to deliver HCM solutions at lower prices, more efficiently or more conveniently, such technologies could adversely impact our ability to compete. We have made significant investments in developing, testing, deploying and supporting AI-powered tools in our solution. Continuing to develop, test, deploy and support resource-intensive AI-powered tools will require additional investment and may increase our costs. To the extent that we do not effectively address server capacity constraints or otherwise upgrade our systems and data centers to accommodate actual and anticipated changes in technology and our client base, we may experience service interruptions and performance issues, which could result in negative publicity, harm to our reputation and decreased demand for our solution, require us to pay significant penalties or fines or subject us to litigation, claims or other disputes, any of which could have an adverse effect on our business, results of operations and financial condition.

The market in which we participate is highly competitive, and if we do not compete effectively, our business, operating results or financial condition could be adversely affected.

The market for HCM software is highly competitive, rapidly evolving and fragmented. If we are unable to compete effectively, our business, operating results or financial condition could be adversely affected. We expect competition to

20

continue to remain intense as new technologies and new market entrants emerge and aggressive pricing and client retention strategies persist. Competition in the HCM solutions market is primarily based on service responsiveness, application quality and reputation, breadth of service and product offering, and price. Certain competitors have access to larger clients and major distribution agreements with consultants, software vendors and distributors and a more established global presence than we do. Certain of our competitors have in the past or may in the future:

adapt more rapidly to new or emerging technologies and changes in client requirements;

develop superior products or services, gain greater market acceptance and expand their product and service offerings more efficiently or rapidly;

offer products and services that we may not offer individually or at all, or bundle products and services in a manner that provides them with a price advantage;

offer products that can be integrated with other software or systems, whereas our single software may not allow for such integration;

develop and implement control processes that drive internal efficiencies, resulting in a better client experience;

establish and maintain partnerships with third parties that enhance and expand their product offering to business clients and employees;

take advantage of acquisition and other opportunities for expansion more readily;

maintain a lower cost basis;

secure contractual terms and implement other client retention strategies that increase our costs to acquire new clients;

adopt more aggressive or desirable pricing policies;

devote greater resources to the promotion, marketing and sale of their products and services; and

devote greater resources to the research and development of their products and services.

Our competitors offer HCM solutions that may overlap with one, several or all categories of the applications we offer. We compete with companies such as Automatic Data Processing, Inc., Dayforce, Inc., Intuit, Inc., Oracle Corporation, Paychex, Inc., Paylocity Holding Corporation, SAP SE, ServiceNow, Inc., Ultimate Kronos Group, Workday, Inc., and other international, national, regional, and local providers. Our competitors provide HCM solutions by various means. Although certain providers continue to deliver legacy enterprise software, most now offer cloud-based solutions, resulting in increased competition for clients seeking the greater flexibility and access to information provided by cloud-based offerings. Furthermore, the HCM industry has experienced an emergence of white label and embedded payroll offerings. The proliferation of white label offerings and products and technologies utilizing embedded payroll systems may adversely affect our competitive position.

In addition, some of our principal competitors offer their products or services at a lower price, which has resulted in pricing pressures. If we are unable to maintain our pricing levels, our operating results would be negatively impacted. In addition, pricing pressures and increased competition generally could hinder our ability to attract and retain clients and could result in reduced sales, reduced margins, losses or the failure of our solution to maintain widespread market acceptance, any of which could adversely affect our business, operating results or financial condition.

Our business depends on our clients’ continued use of our applications, their purchases of additional applications from us and our ability to add new clients. Any decline in our clients’ continued use of our applications or purchases of additional applications could adversely affect our business, operating results or financial condition.

In order for us to maintain or improve our operating results, it is important that our current clients continue to use our applications and purchase additional applications from us, and that we add new clients. Our annual revenue retention rate fluctuates as a result of a number of factors, including but not limited to the level of client satisfaction with our applications, pricing, the prices of competing products or services, mergers and acquisitions affecting our client base, reduced hiring by our clients or reductions in our clients’ spending levels. Many of our clients have the right to cancel their agreements with us for any or no reason by providing 30 days’ prior written notice. Moreover, from time to time, clients choose not to continue to use our applications at the same or higher level of service, if at all. Because we charge our clients on a per employee basis for certain services we provide, the performance of certain of our offerings is sensitive to changes in the labor market. Any increase or decrease in the number of employees of our clients will have a positive or negative impact, respectively, on our results of operations. As technology continues to evolve, more tasks historically performed by people have been and may continue to be replaced by automation, robotics, AI and other technological advances outside of our control, which may reduce our clients’ need for existing or future employees who are or would be potential users of our solution. If our clients reduce headcount, do not continue to use our applications, renew on less favorable terms or fail to purchase additional applications, or if we fail to add new clients, our annual revenue retention rate may decline and our business, operating results or financial condition could be adversely affected.

21

Our business, operating results or financial condition could be adversely affected if our solution fails to perform properly or our clients are not satisfied with our services.

Our solution is inherently complex and may in the future contain, or develop, undetected defects or errors. Any defects in our applications could adversely affect our reputation, impair our ability to sell our applications in the future and result in significant costs to us. The costs incurred to correct any application defects may be substantial and could adversely affect our business, operating results or financial condition. Any defects in functionality or defects that cause interruptions in the availability of our applications could result in:

loss or delayed market acceptance and sales of our applications;

termination of service agreements or loss of clients;

credits, refunds or other liability to clients, including reimbursements for any fees or penalties assessed by regulatory agencies;

breach of contract, breach of warranty or indemnification claims against us, which may result in litigation;

diversion of development and service resources;

increased scrutiny of our solution from regulatory agencies; and

injury to our reputation.

Because of the large amount of data that we collect and manage, it is possible that hardware failures or errors in our applications could result in data loss or corruption or cause the information that we collect to be incomplete or contain inaccuracies that our clients regard as significant. From time to time, our clients assert claims against us alleging that they suffered damages due to a defect, error, or other failure of our solution. We also face potential liability from our clients, and possibly third parties, in the event we fail to report information, particularly wage and earnings information, criminal records or other potentially negative information, or wrongly report such information. From time to time, we have been subject to claims and lawsuits by current and potential employees of our clients, alleging that we provided to our clients inaccurate or improper information that negatively affected the clients. Although the resolutions of these lawsuits have not had a material adverse effect on us to date, the costs of such claims, including settlement amounts or punitive damages, could be material in the future, could cause adverse publicity and reputational damage, could divert the attention of our management, could subject us to equitable remedies relating to the operation of our business and provision of services and result in significant legal expenses, all of which could have a material adverse effect on our business, financial condition and results of operations and adverse publicity, and could result in the loss of existing clients and make it difficult to attract new clients. Our errors and omissions insurance may be inadequate or may not be available in the future on acceptable terms, or at all. In addition, our policy may not cover all claims made against us, and defending a suit, regardless of its merit, could be costly and divert management’s attention. Any failures in the performance of our solution could harm our reputation and our ability to retain existing clients and attract new clients, which would have an adverse impact on our business, operating results or financial condition.

Furthermore, our business depends on our ability to satisfy our clients, both with respect to our applications and the technical support provided to help our clients use the applications that address the needs of their businesses. We use our in-house deployment personnel to implement and configure our solution and provide support to our clients. If a client is not satisfied with the quality of our solution, the applications delivered or the support provided, we could incur additional costs to address the situation, our profitability might be negatively affected, and the client’s dissatisfaction with our deployment or support service could harm our ability to sell additional applications to that client. In addition, our sales process is highly dependent on the reputation of our solution and applications and on positive recommendations from our existing clients. Any failure to maintain high-quality technical support, or a market perception that we do not maintain high-quality technical support, could adversely affect client retention, our reputation, our ability to sell our applications to existing and prospective clients, and, as a result, our business, operating results or financial condition.

We face challenges related to attracting and retaining larger clients, including demand for customized features, longer sales cycles and less predictability in completing sales.

In some cases, prospective clients, especially larger companies, expect customized features and functions unique to their business processes, or are seeking to integrate our solutions with other products. If we do not meet the demands of such prospective clients, the market for our solution will be more limited and our business could be adversely affected. Furthermore, pursing larger clients may result in a longer sales cycle and, in some cases, we may devote a significant amount of support and service resources to attract and acquire larger prospective clients with no guarantee that these prospective clients will adopt our solution.

We are dependent on the leadership of our key executives and, if we fail to retain such key executives, our business could be adversely affected.

We believe the success of our business and execution of our strategy depend, in part, on the leadership of Chad Richison, our founder, Chief Executive Officer and Chairman of the Board of Directors, and that of our other key executive officers and

22

employees. The loss of their leadership, expertise and experience could adversely impact our operations. Effective succession planning is also important to our long-term success. Changes in our management team may be disruptive to our business, and any failure to ensure effective transfer of knowledge or successfully integrate key new hires or promoted employees could adversely affect our business and results of operations. The loss of the services of any of our executive officers or other key employees, or our inability to attract highly qualified senior management and other key personnel, could harm our business. In addition, legal and regulatory developments may affect our ability to enforce post-termination obligations of certain employees with respect to non-competition, non-solicitation and protection of confidential information. Our business could be adversely affected if a key executive leaves Paycom and interferes with our client, employee and/or other business relationships. We do not maintain key man life insurance on any of our executive officers.

If we are unable to attract and retain qualified personnel, including software developers, product managers and skilled IT, sales, marketing and operational personnel, our ability to develop and market new and existing products and, in turn, increase our revenue and profitability could be adversely affected.

Our future success is dependent on our ability to continue to enhance and introduce new applications. As a result, we are heavily dependent on our ability to attract and retain qualified software developers, product managers and IT personnel with the requisite education, background and industry experience. In addition, to continue to execute our growth strategy, we must also attract and retain qualified sales, marketing and operational personnel capable of supporting a larger and more diverse client base. The technology industry is characterized by a high level of employee mobility and aggressive recruiting among competitors, and competition is particularly intense for qualified software developers, product managers and IT personnel. In addition, the nature of the office environment is changing as employers continue to offer various remote or hybrid work arrangements, which can be an important factor in a candidate’s decision on employment. We maintain an office-centric operational model. Certain companies with which we compete for talent offer work arrangements more flexible than ours, which may impact our ability to attract and retain qualified personnel if potential or current employees prefer such policies.

The competition for qualified personnel has been amplified by new immigration laws and policies that limit software companies’ ability to recruit internationally. Although such changes in immigration laws and policies have not had a significant direct impact on our workforce to date, the ensuing increase in demand for software developers and IT personnel could impair our ability to attract or retain skilled employees and/or significantly increase our costs to do so. Furthermore, identifying and recruiting qualified personnel and training them in the use of our applications requires significant time, expense and attention, and it can take a substantial amount of time before our employees are fully trained and productive. The unplanned loss of the services of a significant number of skilled employees could be disruptive to our development efforts, which may adversely affect our business by causing us to lose clients, increase operating expenses or divert management’s attention to recruit replacements for the departed employees.

Our business and operations have experienced significant growth and organizational change. If we fail to manage such growth and change effectively, we may be unable to execute our business plan, maintain high levels of service or adequately address competitive challenges.

We have experienced, and may continue to experience, significant growth in our operations, which has placed, and may continue to place, significant demands on our management, operational and financial resources. We have also experienced significant growth in the number of clients and transactions and the amount of client and employee data that our infrastructure supports. As a result, our organizational structure and recording systems and procedures are becoming more complex as we improve our operational, financial and management controls. Our success depends, in part, on our ability to manage this growth and organizational change effectively. Moreover, our international expansion efforts are exacerbating many of these challenges. To manage the effects of our growth, we must continue to improve our operational, financial and management controls and our reporting systems and procedures. The failure to effectively manage growth could result in (i) declines in the quality of, or client satisfaction with, our applications or service delivery, (ii) increases in costs, (iii) difficulties or delays in introducing new applications or (iv) other operational difficulties, any of which could adversely affect our business by impairing our ability to retain and attract clients or sell additional applications to our existing clients. In addition, our ability to expand our sales force may be constrained by the willingness and availability of qualified personnel to staff and manage new offices and our success in recruiting and training sales personnel. If our expansion efforts are unsuccessful, our business, operating results or financial condition could be adversely affected.

The failure to develop and maintain our brand cost-effectively could have an adverse effect on our business.

We believe that developing and maintaining widespread awareness of our brand in a cost-effective manner is critical to achieving widespread acceptance of our solution and is an important element in attracting new clients and retaining existing clients. Successful promotion of our brand depends largely on the effectiveness of our marketing efforts and on our ability to provide reliable and useful applications at competitive prices. Brand promotion activities, including increased spending on our national media campaigns, may not yield increased revenues, and even if they do, any increased revenues may not offset the expenses incurred in building our brand. If we fail to successfully promote and maintain our brand, or incur substantial expenses in an unsuccessful attempt to promote and maintain our brand, we may fail to attract enough new clients or retain our existing

23

clients to the extent necessary to realize a sufficient return on our brand-building efforts, which could have an adverse effect on our business.

As we continue to enhance our solution to serve clients located outside of the United States, our business is subject to risks associated with international operations.

An element of our growth strategy is to expand our operations and client base, including in markets outside of the United States. Launching into international markets and doing business internationally involves a number of risks, including but not limited to:

multiple, conflicting and changing laws and regulations such as privacy regulations, tax laws, export and import restrictions, employment laws, regulatory requirements and other governmental approvals, permits, and licenses;

failure to obtain and maintain regulatory approvals for the use of our products in various countries;

lack of brand recognition, including greater brand recognition of local or other global competitors who have more established operations in the markets we are seeking to enter;

lack of familiarity with local, regional or national politics, culture, economics, market conditions and commerce;

complexities and difficulties in obtaining protection for and enforcing our intellectual property rights;

difficulties in staffing and managing foreign operations;

financial risks, such as the impact of local and regional financial crises on demand for our products and exposure to foreign currency exchange rate fluctuations;

natural disasters, political and economic instability, including wars, terrorism and political unrest, outbreak of disease, boycotts, curtailment of trade and other business restrictions;

certain expenses including, among others, expenses for travel, translation and insurance; and

regulatory and compliance risks that relate to maintaining accurate information and control over sales and activities that may fall within the purview of the U.S. Foreign Corrupt Practices Act, its books and records provisions or its anti-bribery provisions, as well as similar laws in foreign jurisdictions.

Our expansion into international markets requires significant resources and management attention and subjects us to regulatory, economic and political risks that differ from those in the United States. Because of our inexperience with international operations, we cannot ensure that our expansion into international markets will be successful, and the impact of such expansion may adversely affect our business, operating results or financial condition.

Our business depends in part on the success of our relationships with third parties.

We rely on third-party couriers to deliver payroll checks and tax forms and on financial and accounting processing systems and various financial institutions to perform financial services in connection with our applications, such as providing automated clearing house (“ACH”) and wire transfers as part of our payroll and payroll tax payment services and facilitating our Vault Visa® Payroll Card. We also rely on third parties to provide technology and content support, manufacture time clocks and process background checks. We anticipate that we will continue to depend on various third-party relationships in order to provide these and other services. Identifying, negotiating and documenting relationships with these third parties and integrating third-party content and technology requires significant time and resources. Our agreements with third parties typically are non-exclusive and do not prohibit them from working with our competitors. In addition, these third parties may not perform as expected under our agreements, which could hinder our ability to deliver certain services to our clients and negatively affect our brand and reputation. A global economic slowdown could also adversely affect the businesses of our third-party providers, hindering their ability to provide the services on which we rely. If we are unsuccessful in establishing or maintaining our relationships with these third parties, or the services provided by third parties fail to meet our clients’ or client employees’ expectations, our ability to compete in the marketplace or to grow our revenues could be impaired and our business, operating results or financial condition could be adversely affected. Furthermore, due to our dependence on financial institutions for certain services, a systemic shutdown of the banking industry or a disruption of the Federal Reserve Bank’s services, including ACH processing, would impede our ability to provide our payroll and expense reimbursement services by delaying direct deposits and other financial transactions across the United States and could have an adverse impact on our financial results and liquidity.

We employ third-party licensed software for use in our applications and the inability to maintain these licenses or errors in the software we license could result in increased costs or reduced service levels, which could adversely affect our business.

Our applications incorporate certain third-party software obtained under licenses from other companies. For example, we rely on third-party software to support our background checks application. We anticipate that we will continue to rely on third-party software and development tools from third parties in the future. If the third-party software we currently license becomes unavailable, we may be unable to identify commercially reasonable alternatives without significant cost or difficulty, or

24

available alternatives may not meet our internal cybersecurity requirements. In addition, incorporating the software used in our applications with new third-party software may require significant work and substantial investment of our time and resources. Also, to the extent that our applications depend upon the successful operation of third-party software in conjunction with our software, any undetected errors or defects in this third-party software could prevent the deployment or impair the functionality of our applications, delay new application introductions, or result in a failure of our applications and harm our reputation.

We have licensed and deployed a third-party large language model (“LLM”) on our own internal network and AI-powered tools. This LLM processes a large amount of employee and customer data, including potentially sensitive information. Unauthorized access to or a breach of this LLM software could lead to significant legal and financial repercussions for us. Also, failure to comply with continually evolving privacy, cybersecurity, and AI regulations during our use of this LLM could lead to substantial fines and damage to our reputation. Rapid advancements in technology could quickly render our existing LLM-powered tools obsolete, requiring the licensing and training of a replacement LLM at significant cost to us. The third-party LLM we license was trained on large datasets that may contain biases, and these biases can be reflected in the output of our LLM, leading to potential harm to our employees and/or customers. The third-party LLM may also produce incorrect or inaccurate outcomes, also known as “hallucinations”. The ongoing accuracy of the output of our LLM is critical for its effectiveness, and inaccurate or unreliable outputs could lead to customer dissatisfaction and potential legal liabilities.

The use of open-source software in our applications may expose us to additional risks and harm our intellectual property rights.

Some of our applications use software and models covered by open-source licenses. Usage of open-source software can lead to greater risks than use of third-party commercial software, as open-source licensors generally do not provide warranties, maintenance and support, other contractual protections or controls on the origin of the software. Furthermore, the license terms for certain open-source software or AI models may change, requiring us to pay for a commercial license or re-engineer all or a portion of certain applications or tools, resulting in significant additional costs for us. Open-source software may also present a heightened risk of security vulnerabilities, including due to the intentional acts of malicious actors who inject such vulnerabilities into the code, or to older versions of the software not remaining current with applicable updates and patches to address vulnerabilities or other bugs. From time to time, there have been claims challenging the ownership or use of certain types of open-source software against companies that incorporate such software into their products or applications. As a result, we could be subject to suits by parties claiming ownership of what we believe to be open-source software. Similarly, open-source AI models may be trained on data of unknown or uncertain provenance, which could include copyrighted or otherwise proprietary, confidential, or private information. If our applications incorporate such models, we could face claims for copyright infringement and other violations. Litigation could be costly for us to defend, have a negative effect on our operating results and financial condition or require us to devote additional development resources to change our applications. In addition, if we were to combine our applications with open-source software in a certain manner, we could, under certain types of open-source licenses, be required to release the source code of our applications. If we inappropriately use open-source software, we may be required to redesign our applications or software, discontinue the sale of our applications or software or take other remedial actions, which could adversely impact our business, operating results or financial condition.

Our increasing focus on, and investments in, automation expose us to a number of risks.

A key part of our strategy is our focus on automation. We currently utilize automation and machine learning in certain of our products and services to deliver a better experience for our clients and their employees or customers, and we expect to automate more functions within our solution in the future. We also leverage AI internally to make certain business processes more efficient. While we believe the use of these emerging technologies can present significant benefits, it also creates risks and challenges.

The development and implementation of such advanced technologies is complex. We have invested, and intend to continue to invest, significant time and resources in our automation initiatives, some or all of which may not result in new products or enhancements to our solution or services or, even if deployed, may not materially improve client or client employee experience. Furthermore, existing and prospective clients may be hesitant to adopt products that rely on automation, particularly those that utilize AI. Data sourcing, technology, integration and process issues, programmed bias in decision-making algorithms, concerns over intellectual property, concerns over incorrect or inaccurate outputs, security concerns, and the protection of privacy could impair the adoption and acceptance of our automated solutions. There also may be real or perceived social harm, unfairness, or other outcomes that undermine public confidence in the use and deployment of AI. If our investments in automation initiatives do not result in marketable products or services, or the resulting solutions do not gain market acceptance or we otherwise do not fully realize the intended benefits of these significant investments, our operating results and financial condition may suffer.

In addition, we may incur additional compliance costs to the extent our automation initiatives utilize tools and technologies that are the subject of increasing regulatory and legal scrutiny, such as our AI-powered tools. These laws and regulations are developing and vary from one jurisdiction to another. Future legislative and regulatory action, court decisions or other governmental action may adversely impact our ability to pursue our automation strategy and, in turn, may adversely impact our operations and financial results.

25

If we fail to adequately protect our proprietary rights, our competitive advantage could be impaired and we may lose valuable assets, generate reduced revenues or incur costly litigation to protect our rights.

Our success is dependent in part upon our intellectual property. We rely on a combination of copyrights, trademarks, service marks, trade secret laws and contractual restrictions to establish and to protect our intellectual property rights in the United States and in foreign jurisdictions. However, the steps we take to protect our intellectual property may be inadequate. We will not be able to protect our intellectual property if we are unable to enforce our rights or if we do not detect unauthorized use of our intellectual property. Despite our precautions, it may be possible for unauthorized third parties to copy our applications and use information that we regard as proprietary to create products or services that compete with ours.

We may be required to spend significant resources to monitor and protect our intellectual property. We have been involved in litigation in the past and litigation may be necessary in the future to protect and enforce our intellectual property rights and to protect our trade secrets. Such litigation could be costly, time-consuming and distracting to management and could result in the impairment or loss of portions of our intellectual property. Furthermore, our efforts to enforce our intellectual property rights may be met with defenses, counterclaims and countersuits attacking the validity and enforceability of our intellectual property rights. We may not be able to secure, protect and enforce our intellectual property rights or control access to, and the distribution of, our solution and proprietary information, which could adversely affect our business.

We may be sued by third parties for alleged infringement of their proprietary rights.

Considerable intellectual property development activity exists in our industry, and we expect that companies will increasingly be subject to infringement claims as the number of applications and competitors grows and the functionality of applications in different industry segments overlaps. Our competitors, as well as a number of other entities and individuals, may own or claim to own intellectual property in technology areas relating to our solution or applications. In addition, we may increasingly be subject to trademark infringement claims as our presence grows in the marketplace. From time to time, third parties have asserted and may in the future assert that we are infringing on their intellectual property rights, and we may be found to be infringing upon such rights. A claim of infringement may also be made relating to technology that we acquire or license from third parties. However, we may be unaware of the intellectual property rights of others that may cover, or may be alleged to cover, some or all of our solution, applications or brands.

The outcome of litigation is inherently unpredictable and, as a result, any future litigation or claim of infringement could (i) cause us to enter into an unfavorable royalty or license agreement, pay ongoing royalties or require that we comply with other unfavorable terms, (ii) require us to discontinue the sale of our solution or applications, (iii) require us to indemnify our clients or third-party service providers or (iv) require us to expend additional development resources to redesign our solution or applications. Any of these outcomes could harm our business. Even if we were to prevail, any litigation regarding our intellectual property could be costly and time consuming and divert the attention of our management and key personnel from our business and operations.

We may acquire other businesses, applications or technologies, which could divert our management’s attention, result in additional dilution to our stockholders and otherwise disrupt our operations and harm our operating results.

In the future, we may seek to acquire or invest in businesses, applications or technologies that we believe complement or expand our applications, enhance our technical capabilities or otherwise offer growth opportunities. The pursuit of potential acquisitions may divert the attention of management and cause us to incur expenses in identifying, investigating and pursuing suitable acquisitions, whether or not they are ultimately consummated.

We do not have any experience in acquiring other businesses. If we acquire additional businesses, we may not be able to integrate the acquired personnel, operations and technologies successfully or to effectively manage the combined business following the acquisition. We also may not achieve the anticipated benefits from the acquired business due to a number of factors, including:

the inability to integrate or benefit from acquired applications or services in a profitable manner;

unanticipated costs or liabilities associated with the acquisition;

the incurrence of acquisition-related costs;

difficulty integrating the accounting systems, operations and personnel of the acquired business;

difficulty and additional expenses associated with supporting legacy products and hosting infrastructure of the acquired business;

difficulty converting the clients of the acquired business onto our solution, including disparities in the revenues, licensing, support or services of the acquired company;

diversion of management’s attention from other business concerns;

harm to our existing relationships with clients as a result of the acquisition;

26

the potential loss of key employees;

the use of resources that are needed in other parts of our business; and

the use of substantial portions of our available cash to consummate the acquisition.

In addition, a significant portion of the purchase price of any companies we acquire may be allocated to acquired goodwill and other intangible assets, which must be assessed for impairment at least annually. In the future, if our acquisitions do not yield expected returns, we may be required to take charges to our operating results based on this impairment assessment process, which could harm our results of operations. Acquisitions could also result in the incurrence of debt or issuances of equity securities, which would result in dilution to our stockholders.

Legal and Regulatory Risks

Changes in laws, government regulations and policies could have a material adverse effect on our business and results of operations.

Many of our applications are designed to assist our clients in complying with government regulations that continually change. The introduction of new regulatory requirements, or new interpretations of existing laws or regulations, could increase our cost of doing business, decrease our revenues and net income or require us to make changes to our applications. Moreover, changing regulatory requirements may make the introduction of new applications and enhancements more costly or more time-consuming than we currently anticipate or could prevent the introduction of new applications and enhancements by us altogether.

For example, a change in tax laws and regulations resulting in a decrease in the amount of taxes required to be withheld or accelerating the deadline to remit taxes to appropriate tax agencies would adversely impact our average balance of funds held for clients and, as a result, adversely impact the interest income we earn on such funds during the period between receipt and disbursement. Changes in laws, regulations or policies could also affect the extent and type of benefits employers are required, or may choose, to provide employees or the amount and type of taxes employers and employees are required to pay. Such changes could reduce or eliminate the need for certain of our existing applications or services, which would result in decreased revenues.

Further, we may spend time and money developing new applications and enhancements that, due to regulatory changes, become unnecessary prior to being released. In addition, any failure to educate and assist our clients with respect to new or revised legislation that impacts them could have an adverse effect on our reputation, and any failure to modify our applications or develop new applications in a timely fashion in response to regulatory changes could have an adverse effect on our business and results of operations. Additionally, new regulations or changes to existing regulations could be unclear, difficult to interpret or conflict with other applicable regulations. Our or our clients’ failure to comply with new or modified laws or regulations could result in financial penalties, legal proceedings or reputational harm. Finally, a negative audit or other investigations by the U.S. Government could adversely affect our ability to receive U.S. Government contracts and could result in financial or reputational harm.

In addition, federal, state and foreign government bodies or agencies have in the past adopted, and may in the future adopt, laws or regulations affecting the use of the internet as a commercial medium. Changes in these laws or regulations could require us to modify our applications. Further, government agencies or private organizations may impose taxes, fees or other charges for accessing the internet or commerce conducted via the internet. These laws or charges could limit the growth of internet-related commerce or communications generally or could result in reductions in the demand for internet-based applications such as ours.

Failure to comply with privacy, data protection and cybersecurity laws and regulations could have a materially adverse effect on our reputation, results of operations or financial condition, or have other adverse consequences.

Our applications and services are subject to various complex laws and regulations on the federal, state, local, and foreign levels, including those governing data security, privacy, and AI which have become significant compliance issues globally. The regulatory framework for privacy of personal data is rapidly evolving and is likely to remain uncertain for the foreseeable future. Many federal, state and foreign government bodies and agencies have adopted or are considering adopting laws and regulations regarding the collection, use and disclosure of personal information. In the United States, these include numerous state-level consumer privacy laws, such as California’s CCPA, Texas’ Data Privacy and Security Act, Illinois’ IBIPA, rules and regulations promulgated under the authority of the Federal Trade Commission, the Health Insurance Portability and Accountability Act of 1996, the Family Medical Leave Act of 1993, the ACA, the Financial Services Modernization Act of 1999 (the “GLBA”), the Fair Credit Reporting Act (“FCRA”), federal and state labor and employment laws, state data breach notification laws, and state cybersecurity laws such as the New York Stop Hacks and Improve Electronic Data Security (SHIELD) Act. As we continue to expand our operations outside the United States, our applications and services are or will be subject to additional laws governing data security and privacy in relevant jurisdictions, such as Canada’s PIPEDA and Mexico’s Federal Law on the Protection of Personal Data held by Private Parties, as well as the EU GDPR and United Kingdom’s

27

General Data Protection Regulation, which are applicable in the European Economic Area and the United Kingdom, respectively.

Many of these newer state-level consumer privacy laws give consumers located in those states certain rights, including the right to be informed of, opt-out of, and request deletion of the personal information that we hold, similar to those rights provided by the EU GDPR. Notably, the GLBA is enforced under the authority of the Federal Trade Commission and requires our payment card services to adhere to a privacy notice and take certain measures to protect related personal information from unauthorized use and threats to data security. The FCRA places certain requirements and duties on our business as a furnisher of information to certain consumer reporting agencies with which we share limited amounts of data. Because some of our clients are located in Mexico and other clients have establishments internationally, Canada’s PIPEDA, Mexico’s Federal Law on the Protection of Personal Data, and other foreign data privacy laws, such as the EU GDPR, may impact our processing of certain client and employee information. Failure to comply with data protection and privacy laws and regulations could result in regulatory scrutiny and increased exposure to the risk of litigation or the imposition of consent orders, injunctions against data processing or data exporting, or civil and criminal penalties, including fines, which could have an adverse effect on our results of operations or financial condition. Moreover, allegations of non-compliance with privacy laws, whether or not true, could be costly, time consuming, distracting to management, and cause reputational harm. The landscape of privacy laws applicable to our various products and services is evolving quickly. The CPRA, which expands upon the CCPA, went into effect in 2023. Numerous other states have now enacted their own consumer data privacy statutes, many of which are modeled on the CCPA, including states like Colorado, Connecticut, Delaware, Oregon, Montana, Nebraska, New Hampshire, New Jersey, Utah, Virginia, Iowa, and Tennessee. In addition, there are a number of other legislative proposals in jurisdictions across the world for comprehensive privacy laws affecting consumer and employee personal information, which could impose additional and potentially conflicting obligations in areas affecting our business. Newly-passed legislative and regulatory initiatives may adversely affect the ability of our clients to process, handle, store, use and transmit demographic and personal information from their employees, which could reduce demand for our services.

On May 21, 2024, the European Union legislators approved the EU AI Act, which establishes a comprehensive, risk-based governance framework for AI in the EU market. The EU AI Act went into effect on August 2, 2024, and the majority of the substantive requirements will go into effect on August 2, 2026. The EU AI Act, and developing interpretation and application of the EU GDPR in respect of automated decision making, together with developing guidance and/or decisions in this area, may affect our use of AI technologies and our ability to provide, improve or commercialize our business, require additional compliance measures and changes to our operations and processes, result in increased compliance costs and potential increases in civil claims against us, and could adversely affect our business, operations and financial condition.

In addition to government regulation, privacy advocates and industry groups may propose and adopt new and different self-regulatory standards. Because the interpretation and application of many privacy and data protection laws are still uncertain, it is possible that these laws may be interpreted and applied in a manner that is inconsistent with our existing data management practices or the features of our solution. Any failure to comply with government regulations that apply to our applications, including privacy and data protection laws, could subject us to liability. In addition to the possibility of fines, lawsuits and other claims, we could be required to fundamentally change our business activities and practices or modify our solution, which could have an adverse effect on our business, operating results or financial condition. Any inability to adequately address privacy concerns and claims, even if unfounded, or inability to comply with applicable privacy or data protection laws, regulations and policies, could result in additional cost and liability to us, damage to our reputation, reductions in our sales and other adverse effects on our business, operating results or financial condition.

Furthermore, privacy concerns may cause our clients’ employees to resist providing the personal data necessary to allow our clients and their employees to use our applications and services effectively. Even the perception of privacy concerns, whether or not valid, may inhibit market adoption of our applications and services in certain industries.

Certain of our products and services use data-driven insights to help our clients manage their businesses more efficiently. Our business increasingly relies on AI and machine learning to model and create these insights. Use of these methods has recently come under increased regulatory scrutiny. New laws, guidance and court decisions in this area may limit our ability to use AI tools, or require us to make changes to our application or services that may decrease our operational efficiency, result in an increase to operating costs and hinder our ability to improve our services. For example, rules on the use of automated decision-making under enacted and proposed data protection laws may require us to disclose the existence of automated decision-making to the data subject with an explanation of the logic used in such decision-making, and may require us to implement certain safeguards, including the right to obtain human intervention and to contest any decision. Regulatory and legislative authorities in the United States and other countries have proposed similar types of legislation that imposes or would impose restrictions on the development of generative AI and machine learning. Our ability to provide data-driven insights using generative AI or machine learning may be constrained by current or future regulatory requirements, statutes or ethical considerations that could restrict or impose burdensome and costly requirements on our ability to leverage data in innovative ways. As we continue to pursue such new technologies, our failure to adequately address legal risks relating to the use of generative AI and machine learning in our applications could result in litigation or private action that could result in liability for the Company. Any actual or alleged noncompliance with these new laws and regulations, or failure to meet client expectations

28

with respect to the use of generative AI and machine learning, could also result in negative publicity or harm to our reputation, subject us to investigations and expose us to significant fines, penalties and other damages.

The adoption of new, or adverse interpretations of existing U.S. state, U.S. federal, or foreign money transmitter, money services business, or payment services statutes or regulations could subject us to additional regulation and related expenses and require changes to our business.

The adoption of new money transmitter, money services business, or payment services statutes or regulations in jurisdictions, changes in regulators’ interpretation of existing U.S. state, U.S. federal, or foreign money transmitter, money services business, or payments services statutes or regulations, or disagreements by regulatory authorities with our interpretation of such statutes or regulations, have subjected us to registration or licensing and could limit business activities until we are appropriately licensed. These occurrences could also require changes to the manner in which we conduct certain aspects of our business or invest client funds, which could adversely impact the amount of interest income we receive from investing client funds before such funds are remitted to the appropriate taxing authorities and accounts designated by our clients.

As the Paycom National Trust Bank now manages U.S. client money movement activity, these transmissions are federally exempt from state money transmitter regulation, and we have surrendered all historically maintained state money transmitter licenses. Outside of the United States, we maintain certain “money services business” registrations and intend to apply for, where necessary, money services business, money transmitter, payment services provider, or similarly named applicable licenses.

Should other U.S. state, U.S. federal, or foreign regulators make a determination that we have operated as an unlicensed money services business, money transmitter, or payment services provider, we could be subject to civil and criminal fines, penalties, costs of registration, legal fees, reputational damage or other negative consequences, any of which may have an adverse effect on our business operating results or financial condition.

While we maintain we are not a money services business or money transmitter in the United States and other jurisdictions, our operations in certain jurisdictions in and outside of the U.S. are subject to AML laws and regulations, including, for example, the BSA. Among other things, the BSA requires certain financial institutions, including banks and money services businesses, to develop and implement risk-based AML programs, report large cash transactions and suspicious activity, and maintain transaction records. We have adopted an AML compliance program to mitigate the risk of our application being used for illegal or illicit activity and to help detect and prevent fraud. Our AML compliance program is designed to foster trust in our application and services. However, there can be no assurance that our employees, consultants, or agents will not take actions in violation of our policies for which we may be ultimately responsible, or that our policies and procedures will be adequate or will be determined to be adequate by regulators. Any violation of applicable AML laws or regulations could limit certain of our business activities until they are satisfactorily remediated and could result in civil and criminal penalties, including fines, which could damage our reputation and have a materially adverse effect on our results of operations and financial condition.

Further, bank regulators continue to impose additional and stricter requirements on banks to ensure they are meeting their BSA obligations, and banks are increasingly viewing money services businesses and third-party senders to be higher risk customers for money laundering. Thus, our banking partners that assist in processing our money movement transactions may limit the scope of services they provide to us or may impose additional material requirements on us. These regulatory restrictions on banks and changes to banks’ internal risk-based policies and procedures may result in a decrease in the number of banks willing to do business with us, may require us to materially change the manner in which we conduct some aspects of our business, may decrease our revenues and earnings and could have a material adverse effect on our results of operations or financial condition.

Adverse tax laws or regulations could be enacted or existing laws could be applied to us or our clients, which could increase the costs of our solution and applications and could adversely affect our business, operating results or financial condition.

As a vendor of services, we are ordinarily held responsible by taxing authorities for collecting and paying any applicable sales or other similar taxes. Additionally, the application of tax laws to services provided electronically like ours is evolving. New income, sales, use or other tax laws, statutes, rules, regulations or ordinances could be enacted at any time (possibly with retroactive effect), and could be applied solely or disproportionately to services and applications provided over the internet. These enactments could adversely affect our sales activity, due to the inherent cost increase the taxes would represent, and ultimately could adversely affect our business, operating results or financial condition.

Each jurisdiction has different rules and regulations governing sales and use taxes, and these rules and regulations are subject to varying interpretations that change over time. We review these rules and regulations periodically and, when we believe we are subject to sales and use taxes in a particular jurisdiction, we may voluntarily engage the applicable tax authorities in order to determine how to comply with that jurisdiction’s rules and regulations. We cannot ensure that we will not be subject to sales and use taxes or related penalties for past sales in jurisdictions where we currently believe no such taxes are required.

29

In addition, existing tax laws, statutes, rules, regulations or ordinances could be interpreted, changed, modified or applied adversely to us (possibly with retroactive effect), which could require us or our clients to pay additional tax amounts, as well as require us or our clients to pay fines or penalties and substantial interest for past amounts. If we are unsuccessful in collecting such taxes from our clients, we could be held liable for such costs, thereby adversely affecting our business, operating results or financial condition. Additionally, the imposition of such taxes on us would effectively increase the cost of our software and services we provide to clients and would likely have a negative impact on our ability to retain existing clients or to gain new clients in the jurisdictions in which such taxes are imposed.

Compliance with employment-related laws and regulations could increase our cost of doing business and violations of such laws and regulations could subject us to fines and lawsuits.

Our operations are subject to a variety of federal, state, local and international employment-related laws and regulations, including, but not limited to, the U.S. Fair Labor Standards Act, which governs such matters as minimum wages, the Family Medical Leave Act, overtime pay, compensable time, recordkeeping and other working conditions, Title VII of the Civil Rights Act, the Employee Retirement Income Security Act, the Americans with Disabilities Act, the National Labor Relations Act, regulations of the Equal Employment Opportunity Commission, regulations of the Office of Civil Rights, regulations of the Department of Labor, regulations of state attorneys general, federal and state wage and hour laws, and a variety of similar laws enacted by the federal and state governments that govern these and other employment-related matters. As our employees are located in a number of states and countries, compliance with evolving laws and regulations could substantially increase our cost of doing business. In recent years, we have been subject to threatened and filed lawsuits, including class action lawsuits, alleging violations of federal and state law regarding workplace and employment matters, overtime wage policies, discrimination and similar matters. We may incur damages and expenses resulting from lawsuits of this type, which could have a material adverse effect on our business, financial condition or results of operations. We are currently subject to employee-related legal proceedings in the ordinary course of business. While we believe that we have adequate reserves for those losses that we believe are probable and can be reasonably estimated, the ultimate results of legal proceedings and claims cannot be predicted with certainty.

While none of our employees are currently represented by a union, our employees have the right under the National Labor Relations Act to form or affiliate with a union. If a significant portion of our employees were to become unionized, our labor costs could increase and our business could be negatively affected by other requirements and expectations that could increase our costs, change our employee culture, impact corporate flexibility and disrupt our business. Additionally, our responses to any union organizing efforts could negatively impact perception of our brand and have adverse effects on our business, including on our financial results. These responses could also expose us to legal risk, causing us to incur costs related to defending legal and regulatory actions, potential penalties and restrictions or reputational harm.

Our background check business is subject to significant governmental regulation, and changes in law or regulation, or a failure to correctly identify, interpret, comply with and reconcile the laws and regulations to which it is subject, could materially adversely affect our revenue or profitability.

We offer a background screening application called Enhanced Background Checks. In the course of providing background checks, we search and report public and non-public consumer information and records, including criminal records, employment and education history, credit history, driving records and drug screening results. Consequently, we are subject to extensive, evolving and often complex laws and governmental regulations, such as the FCRA, the Drivers’ Privacy Protection Act, state consumer reporting agency laws, state licensing and registration requirements, and various other foreign, federal, state and local laws and regulations. These laws and regulations set forth restrictions and process requirements concerning what may be reported about an individual, when, to whom, and for what purposes, and how the subjects of background checks are to be treated. Compliance with these laws and regulations requires significant expense and resources, which could increase significantly as these laws and regulations evolve. Such increase in restrictions and compliance costs could negatively affect our ability to provide other services expected by our clients and adversely affect our offerings and revenue.

Changes in law, regulation, or administrative enforcement and interpretations or other limitations and prohibitions related to the provision of consumer information and records could materially adversely affect our revenue and profitability. For example, numerous state and local authorities have implemented “ban the box” and “fair chance” hiring laws that limit or prohibit employers from inquiring or using a candidate’s criminal history to make employment decisions, and many of these authorities have in recent years amended these laws to increase the restrictions on the use of such information. In addition, redaction of personal identifying information in criminal records (such as date of birth), and court rules or lawsuits that limit or restrict access to identifiers in criminal records, may negatively impact our ability to perform complete criminal background checks. The enactment of new restrictive legislation and the requirements, restrictions, and limitations imposed by changing interpretations and court decisions on such laws and regulations could prevent our customers from using the full functionality of our background screening application, which may reduce demand for such solution.

Furthermore, we face potential liability from individuals, classes of individuals, clients or regulatory bodies for claims based on the nature, content or accuracy of our background check services and the information we use and report. Our potential exposure to lawsuits or government investigations may increase depending in part on our clients’ compliance with these laws

30

and regulations and applicable employment laws in their procurement and use of our background checks as part of their hiring process, which is generally outside of our control. Our potential liability includes claims of non-compliance with the FCRA, U.S. state consumer reporting agency laws or regulations, foreign regulations or applicable employment laws, as well as other claims of defamation, invasion of privacy, negligence, copyright, patent or trademark infringement. In some cases, we may be subject to strict liability.

Industry and Financial Risks

Our financial results may fluctuate due to many factors, some of which may be beyond our control.

Our results of operations, including our revenues, costs of revenues, administrative expenses, operating income, cash flow and deferred revenue, may vary significantly in the future, and the results of any one period should not be relied upon as an indication of future performance. Fluctuations in our financial results may negatively impact the value of our common stock. Our financial results may fluctuate as a result of a variety of factors, many of which are outside of our control, and as a result, may not fully reflect the underlying performance of our business. Factors that may cause our financial results to fluctuate from period to period include, without limitation:

our ability to attract new clients or sell additional applications to our existing clients;

the number of new clients and their employees, as compared to the number of existing clients and their employees in a particular period;

the mix of clients between small, mid-sized and large organizations;

the extent to which we retain existing clients and the expansion or contraction of our relationships with them;

the mix of applications sold during a period;

changes in our pricing policies or those of our competitors;

seasonal factors affecting payroll processing, demand for our applications or potential clients’ purchasing decisions;

the amount and timing of operating expenses, including those related to the maintenance and expansion of our business, operations and infrastructure;

the timing and success of new applications introduced by us and the timing of expenses related to the development of new applications and technologies;

the timing and success of current and new competitive products and services offered by our competitors;

economic conditions affecting our clients, including their ability to outsource HCM solutions and hire employees;

changes in laws, regulations or policies affecting our clients’ legal obligations and, as a result, demand for certain applications;

changes in the competitive dynamics of our industry, including consolidation among competitors or clients;

our ability to manage our existing business and future growth, including expenses related to our data centers and the expansion of such data centers and the addition of new offices;

the effects and expenses of acquisition of third-party technologies or businesses and any potential future charges for impairment of goodwill resulting from those acquisitions;

business disruptions caused by widespread public health crises, natural disasters, such as tornadoes, hurricanes, fires, earthquakes and floods (including as a result of climate change), acts of war, terrorism, or other catastrophic events;

network outages or security breaches; and

general economic, industry and market conditions.

Certain of our operating results and financial metrics may be difficult to predict as a result of seasonality.

We have historically experienced seasonality in our revenues. A significant portion of our recurring revenues relate to the annual processing of payroll tax filing forms such as Form W-2 and Form 1099 and the annual processing and filing of ACA-related forms. These forms are typically processed in the first quarter of the year and, as a result, positively impact first quarter recurring revenues. In addition, unscheduled payroll runs at the end of the year (such as bonuses) have a positive impact on our recurring revenues in the fourth quarter. Although we expect the magnitude of seasonal fluctuations in our revenues to decrease in the future to the extent clients utilize more of our non-payroll applications, seasonal fluctuations in certain of our operating results and financial metrics may make such results and metrics difficult to predict.

31

We are subject to certain operating and financial covenants that may restrict our business and financing activities and may adversely affect our cash flow and our ability to operate our business.

We maintain a Revolving Credit Facility, which can be accessed as needed to supplement our operating cash flow and cash balances. Although we do not currently have any outstanding indebtedness, pursuant to the Credit Agreement (as defined herein) that governs the Revolving Credit Facility, we may not, subject to certain exceptions:

create or permit the existence of additional liens on our assets;

incur additional debt;

change the nature of our business;

make investments in and acquisitions of (or acquisitions of substantially all of the assets of) any person;

permit certain fundamental changes, including a merger;

dispose of assets;

make any distributions during an event of default, or any other distributions in excess of $50 million in any fiscal year without demonstrating pro forma compliance with certain financial covenants;

enter into transactions with affiliates other than in the ordinary course of business on an arm’s-length basis;

enter into certain transactions, including swap agreements and sale and leaseback transactions; or

pay dividends or distributions of our capital stock.

In addition, we are required to maintain as of the end of each fiscal quarter a consolidated interest coverage ratio of not less than 3.0 to 1.0 and a consolidated leverage ratio of not greater than 3.0 to 1.0. The operating and financial covenants in the Credit Agreement, as well as any future financing agreements that we may enter into, may restrict our ability to finance our operations, engage in business activities or expand or fully pursue our business strategies. If we borrow in the future, we may be required to use a substantial portion of our cash flows to pay principal and interest on our debt, which would reduce the amount of money available for operations, working capital, expansion, or other general corporate purposes.

Our ability to meet our expenses and debt obligations and comply with the operating and financial covenants may be affected by financial, business, economic, regulatory and other factors beyond our control. We may be unable to control many of these factors and comply with these covenants. A breach of any of the covenants under our Credit Agreement could result in an event of default, which could result in the acceleration of any outstanding indebtedness or foreclosure on our assets pledged to secure the indebtedness.

If we are unable to maintain effective internal control over financial reporting, investors may lose confidence in the accuracy and completeness of our financial reports and the market price of our common stock may be negatively affected.

As a public company, we are required to maintain internal control over financial reporting to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements. Management must evaluate and furnish a report on the effectiveness of our internal control over financial reporting as of the end of each fiscal year, and our auditors must attest to the effectiveness of our internal control over financial reporting.

If we have a material weakness in our internal control over financial reporting, we may not detect errors on a timely basis and our financial statements may be materially misstated. If we identify material weaknesses in our internal control over financial reporting or if our independent registered public accounting firm is unable to express an opinion as to the effectiveness of our internal control over financial reporting, investors may lose confidence in the accuracy and completeness of our financial reports and/or we could become subject to investigations by the New York Stock Exchange (the “NYSE”), the SEC, or other regulatory authorities, and the market price of our common stock could be negatively affected.

Our actual operating results may differ significantly from our guidance.

We have released, and may continue to release, guidance in our earnings conference calls, earnings releases, or otherwise, regarding our future performance, which represents our estimates as of the date of release. This guidance, which includes forward-looking statements, has been and will be based on projections prepared by our management. These projections are not prepared with a view toward compliance with published guidelines of the American Institute of Certified Public Accountants, and neither our registered public accountants nor any other independent expert or outside party compiles or examines the projections. Accordingly, no such person expresses any opinion or any other form of assurance with respect to the projections.

Projections are based upon a number of assumptions and estimates that, while presented with numerical specificity, are inherently subject to significant business, economic, and competitive uncertainties and contingencies, many of which are beyond our control. Projections are also based upon specific assumptions with respect to future business decisions, some of which will change. The principal reason that we release guidance is to provide a basis for our management to discuss our

32

business outlook with analysts and investors. We do not accept any responsibility for any projections or reports published by any third parties.

Guidance is necessarily speculative in nature, and it can be expected that some or all of the assumptions underlying the guidance furnished by us will vary significantly from actual results. Accordingly, our guidance is only an estimate of what management believes is realizable as of the date of release. Actual results have in the past, and may in the future, vary from our guidance, and the variations may be material. In light of the foregoing, investors are urged not to rely upon our guidance in making an investment decision regarding our common stock.

Any failure to successfully implement our operating strategy or the occurrence of any of the events or circumstances set forth in this “Risk Factors” section in this Form 10-K could result in the actual operating results being different from our guidance, and the differences may be adverse and material.

Risks Related to Ownership of Our Securities

The issuance of additional stock in connection with acquisitions, our stock incentive plans, warrants or otherwise will dilute all other stockholders.

Our certificate of incorporation authorizes us to issue up to 100 million shares of common stock and up to 10 million shares of preferred stock with such rights and preferences as may be determined by our board of directors. Subject to compliance with applicable rules and regulations, we may issue all of these shares that are not already outstanding without any action or approval by our stockholders. We intend to continue to evaluate strategic acquisitions in the future. We may pay for such acquisitions, in part or in full, through the issuance of additional equity securities.

Any issuance of shares in connection with an acquisition, the exercise of stock options or warrants, the award of shares of restricted stock or otherwise would dilute the percentage ownership held by our existing stockholders.

Anti-takeover provisions in our charter documents and Delaware law may delay or prevent an acquisition of our company.

Our certificate of incorporation, bylaws and Delaware law contain provisions that may have the effect of delaying or preventing a change in control of us or changes in our management. These provisions, alone or together, could delay or prevent hostile takeovers and changes in control or changes in our management.

Any provision of our certificate of incorporation, bylaws or Delaware law that has the effect of delaying or deterring a change in control could limit the opportunity for our stockholders to receive a premium for their shares of our common stock, and could affect the price that some investors are willing to pay for our common stock.

Our certificate of incorporation contains an exclusive forum provision that may discourage lawsuits against us and our directors and officers.

Our certificate of incorporation provides that, unless we consent in writing to the selection of an alternative forum, the Court of Chancery of the State of Delaware (or if no Court of Chancery located within the State of Delaware has jurisdiction, the Federal District Court for the District of Delaware) will be the sole and exclusive forum for any derivative action or proceeding brought on our behalf, any action asserting a claim of breach of fiduciary duty owed by any of our directors, officers or other employees to us or our stockholders, any action asserting a claim against us or any of our directors, officers or other employees arising pursuant to any provision of Delaware law or our certificate of incorporation or our bylaws (as either may be amended from time to time) or any action asserting a claim against us or any of our directors, officers or other employees governed by the internal affairs doctrine. This exclusive forum provision applies to state and federal law claims, although our stockholders will not be deemed to have waived our compliance with the federal securities laws and the rules and regulations thereunder. In addition, this exclusive forum selection provision will not apply to claims under the Exchange Act. Moreover, Section 22 of the Securities Act creates concurrent jurisdiction for federal and state courts over all suits brought to enforce any duty or liability created by the Securities Act or the rules and regulations thereunder. Accordingly, there is uncertainty as to whether a court would enforce our forum selection provision as written in connection with claims arising under the Securities Act. This forum selection provision may limit our stockholders’ ability to obtain a favorable judicial forum for disputes with us. It is also possible that, notwithstanding the forum selection clause included in our certificate of incorporation, a court could rule that such a provision is inapplicable or unenforceable.

We may not continue to pay dividends at the same rate or at all.

Our payment of dividends, as well as the rate at which we pay dividends, are solely at the discretion of our Board of Directors. Further, dividend payments, if any, are subject to our financial results and the availability of statutory surplus. These factors could result in a change to our dividend policy.

33

General Risks

Adverse economic and market conditions could affect our business, operating results or financial condition.

Our business depends on the overall demand for HCM applications and on the economic health of our current and prospective clients. If economic conditions in the United States or in global markets deteriorate, clients may cease their operations, eliminate or reduce unscheduled payroll runs (such as bonuses), reduce headcount, delay or reduce their spending on HCM and other outsourcing services or attempt to renegotiate their contracts with us. In addition, global and regional macroeconomic developments, such as changes in global trade policies and tariffs, increased unemployment, decreased income, uncertainty related to future economic activity, reduced access to credit, increased interest rates, inflation, volatility in capital markets, and decreased liquidity, among other possible factors, could negatively affect our ability to conduct business. Furthermore, the impact of such macroeconomic developments may be exacerbated by geopolitical events and ongoing military conflicts throughout the world. An economic decline could result in reductions in sales of our applications, decreased revenue from unscheduled payroll runs and fees charged on a per-employee basis, longer sales cycles, slower adoption of new technologies and increased price competition, any of which could adversely affect our business, operating results or financial condition. In addition, HCM spending levels may not increase following any recovery.

Further, as part of our payroll and payroll tax filing services, we collect and then remit client funds to taxing authorities and accounts designated by our clients. During the interval between receipt and disbursement, we typically invest such funds in money market funds, demand deposit accounts, certificates of deposit, U.S. treasury securities and commercial paper. These investments are subject to general market, interest rate, credit and liquidity risks, and such risks may be exacerbated during periods of unusual financial market volatility. Any loss of or inability to access such funds could have an adverse impact on our cash position and results of operations and could require us to obtain additional sources of liquidity, which may not be available on terms that are acceptable to us, if at all. Furthermore, although increased interest rates may have a negative impact on certain clients, increased interest rates have resulted in increased interest earned on funds held for clients and additional income earned on our corporate funds. Changes in interest rates will impact potential earnings of future investments. A stable or rising interest rate environment would sustain the additional interest earned on funds held for clients and interest earned on our corporate funds, whereas a decreasing interest rate environment would compress the additional interest earnings and potentially adversely affect our operating results.

In recent years, there have been several instances when there has been uncertainty regarding the ability of Congress and the President collectively to reach agreement on federal budgetary and spending matters. A period of failure to reach agreement on these matters, particularly if accompanied by an actual or threatened government shutdown, may have an adverse impact on the U.S. economy. Additionally, because certain of our clients rely on government resources to fund their operations, a prolonged government shutdown may affect such clients’ ability to make timely payments to us, which could adversely affect our operations results or financial condition.

Item 1B. Unresolved Staff Comments

None.

34

Item 1C. Cybersecurity

Risk Management and Strategy

Overview

We recognize that our clients entrust us with highly sensitive data. We also recognize our attendant responsibility to safeguard the accessibility, confidentiality, and integrity of this data. Our information security program consists of policies, procedures, systems, controls and technology designed to help us prevent, identify, detect and mitigate cybersecurity risks. Our processes are informed by cybersecurity events we have observed within the Company, across our industry, and across the cybersecurity landscape. We utilize the risk management framework for risk assessments as defined by the ISO 27001 Information Security Management Standard. We have integrated cybersecurity risk management into our overall risk management framework by conducting annual enterprise risk management assessments and IT risk management assessments, implementing periodic key risk indicator tracking, and holding periodic meetings among multiple department stakeholders to address cybersecurity risks. We review our information security policies at least annually and in connection with certain process changes to ensure that they meet the needs of the organization and the goals and objectives of the information security program.

Prevention, Identification, Detection and Mitigation Activities

We routinely undertake activities to prevent, identify, detect and mitigate risks from cybersecurity threats, including but not limited to the following:

Procedures and guidelines designed to ensure that information security is a key consideration in the requirements for both new information systems and enhancements to existing systems and assets;

IT environment risk assessments conducted at regular intervals and in connection with certain events, such as implementation of a new system, service or vendor;

Tabletop and simulation exercises to discuss roles and responsibilities of team members in the event of a cybersecurity incident and to test and modify the plan as needed;

Ongoing security penetration testing and threat modeling of our network and web application;

Automated tools and manual review processes to ensure ongoing compliance with technical standards and identify configuration issues and technical vulnerabilities;

Encryption of all communications with our servers, which are configured to utilize only high-grade encryption algorithms; and

Ongoing employee training related to information security and data privacy policies and standards, including periodic phishing, vishing, and social engineering exercises.

We also have implemented and continue to maintain policies, procedures, systems, controls and technology to oversee and identify the cybersecurity risks associated with our use of third-party service providers. For example, we conduct thorough cybersecurity risk assessments of all third-party service providers prior to engagement and ongoing monitoring to ensure compliance with our robust cybersecurity requirements. The monitoring includes periodic audits of third-party systems and vendors. We engage third-party consultants and auditors in connection with assessing, identifying and managing material risks from cybersecurity threats. Our collaboration with these third parties includes independent audits, threat assessments, and consultation on security enhancements.

Infrastructure; Network and Physical Security

Source: SEC EDGAR (public domain) · 10-K for the period ended 2025-12-31, filed 2026-02-19 · accession 0001193125-26-059372

Filing HTML rendered to line-structured narrative text by the shipped reducer (datafeeds.edgar_fulltext.visible_text, keep_table_headers=True): scripts and inline-XBRL headers are dropped, and table content is reduced to its short label cells — numeric table data is not rendered and is therefore not counted. The same rendering is used for every year, so a year-over-year comparison is like for like.

The text is our rendering of the filing, not a facsimile: original pagination, typography and tables are not reproduced, and the numbers live in the financial statements (FA).

The outline locates item HEADINGS in this document. Only Items 1A and 7 have certified boundaries elsewhere in the terminal (the redline and the narrative-overlap number); every span here runs from one heading found to the next heading found.

How the outline was chosen. It is the longest chain of item headings that runs forward through both the document and the standard item order: 23 headings are on that chain and 17 further heading-shaped lines are not — the table-of-contents echo of every item, cross-references and exhibit-list mentions. Each entry's length is measured from its heading to the next heading on the chain.