1 unchanged sentence
Cybersecurity
−Removed: We face various cybersecurity threats as a prominent target, including denial-of-service attacks, ransomware, phishing, and advanced persistent threats.
+Added: We face various cybersecurity threats as a prominent target, including denial-of-service attacks, ransomware, phishing, theft of intellectual property, and advanced persistent threats.
As an aerospace and defense company providing advanced defense technologies and services to the U.S.
2 unchanged sentences
Cybersecurity incidents impacting us, or any of these third parties, could have a material adverse effect on our operations, financial condition, and results of operations.
−Removed: Given the cybersecurity risks we face, we dedicate ample resources to addressing and mitigating our cyber risks.
+Added: Given the cybersecurity risks we face, we believe we dedicate ample resources to addressing and mitigating our cyber risks.
Risk Management and Strategy
Our cybersecurity program is designed to identify, detect, protect against, respond to, and recover from cyber risks and incidents.
−Removed: Our cybersecurity program is part of our internal risk management processes, and we continually improve our cybersecurity practices as new threats and vulnerabilities emerge.
−Removed: Our Chief Information Officer (“CIO”), Chief Information Security Officer (“CISO”), and Vice President of Cybersecurity, all within our “CIO organization,” lead our Detection and Response Team (“DART”) which is responsible for our cybersecurity incident response processes pursuant to our Incident Response Plan and playbooks.
−Removed: The DART also includes members of our IT department responsible for supporting the technologies and processes to protect against, detect, contain, mitigate, and recover from cybersecurity incidents.
−Removed: The DART evaluates and assigns severity levels to cybersecurity incidents and, based on the severity, escalates and engages incident response teams to respond to and mitigate the risks.
+Added: Our cybersecurity program is part of our internal risk management processes, and we improve our cybersecurity practices as new threats and vulnerabilities emerge.
+Added: Our Chief Information Officer (“CIO”) and Chief Information Security Officer (“CISO”) / Vice President of Cybersecurity, both within our CIO organization, are responsible for protecting the company from cybersecurity threats.
+Added: Incidents are triaged, contained and remediated pursuant to our Incident Response Plan and playbooks.
+Added: This process also includes leadership and members of our IT, Legal, Security, Marketing and Communications, and other departments responsible for supporting the technologies and processes to protect against, detect, contain, mitigate, and recover from cybersecurity incidents.
Our cybersecurity team proactively hunts for cyber threats and vulnerabilities in our networks and information systems as part of our cyber risk management program.
This includes monitoring our networks and systems for indicators of compromise (“IOCs”), active intrusion attempts, and other suspicious activity, including insider threat risks.
+Added: The Security Operations Center team evaluates and assigns severity levels to cybersecurity incidents and, based on the severity, escalates and engages incident response teams to respond to and mitigate the risks.
The cybersecurity team stays apprised of existing and emerging cybersecurity threats through commercial threat intelligence feeds and by partnering and data sharing with third parties such as the U.S.
government, law enforcement agencies, customers, and other Defense Industrial Base (“DIB”) participants.
−Removed: We also engage third parties to conduct
−Removed: evaluations of our cybersecurity controls by performing penetration testing and controlled cybersecurity framework audits.
+Added: We also engage third parties to conduct evaluations of our cybersecurity controls by performing penetration testing and controlled cybersecurity framework audits.
We also review the cybersecurity practices of our third-party service providers and suppliers .
1 unchanged sentence
Employees with certain roles and responsibilities are also assigned cyber training for their specific functions.
−Removed: We also maintain an Insider Threat program, headed by our Director of Security, to identify, assess, and deal with potential risks from within our company, including cybersecurity risks.
−Removed: We have aligned our cybersecurity program to the National Institute of Standards and Technology’s (“NIST”) published cybersecurity standards, and our policies and processes are compliant with NIST Special Publication 800-171 and other applicable publications.
−Removed: Given our status as a defense contractor, we are subject to numerous regulations, including those pursuant to the Defense Federal Acquisition Regulation Supplement (“DFARS”), requiring us to have controls in place to protect U.S.
−Removed: government CUI and to report cybersecurity incidents to the DoD.
−Removed: We are also subject to the DoD CMMC requirements which necessitates that companies receiving, storing, or processing federal contract information (“FCI”) and CUI be formally assessed by a CMMC C3PAO.
−Removed: AeroVironment, Inc., including its subsidiaries Arcturus UAS and Tomahawk Robotics (but excluding any of the BlueHalo acquired entities) is scheduled for a formal Level 2 assessment.
−Removed: The recently acquired BlueHalo passed a formal CMMC Level 2 assessment under the CMMC 2.0 framework, which went into effect December 16, 2024.
−Removed: If we fail to achieve or maintain certification ahead of contract awards, or if we fail to achieve the level required for a particular contract, we will be unable to bid on new contracts or follow-on efforts containing CMMC clauses, which could adversely impact the success of our operations.
−Removed: Additionally, our subcontractors and certain vendors may need to obtain CMMC certification, and we may be negatively impacted if they are not compliant with the CMMC requirements.
−Removed: Our CIO, CISO, and VP of Cybersecurity , each with 20+ years of related experience, are responsible for the day-to-day management of our cybersecurity program and cybersecurity risks.
+Added: We also maintain an Insider Threat program, headed by our CISO, to identify, assess, and deal with potential risks from within our company, including cybersecurity risks.
+Added: We have aligned our cybersecurity program to the Cybersecurity Maturity Model Certification (“CMMC”) program.
+Added: Given the diverse nature of our U.S.
+Added: business and foreign business, other frameworks and requirements may also be used and may impose compliance demands beyond those currently anticipated.
+Added: We are also subject to numerous legal requirements, including those governing privacy and data protection requirements and others pursuant to the Federal Acquisition Regulation (“FAR”), agency supplements to the FAR, such as the Defense Federal Acquisition Regulation Supplement (“DFARS”), other regulatory requirements imposing controls for protecting information, including U.S.
+Added: government Controlled Unclassified Information (“CUI”), International Traffic in Arms Regulations (“ITAR”), as well as requirements for reporting cybersecurity incidents to the relevant regulators.
+Added: If we fail to achieve or maintain CMMC certification ahead of contract awards from the DoD, or if we fail to achieve the level required for a particular contract, we will be unable to bid on new contracts or follow-on efforts containing CMMC clauses, which could adversely impact the success of our operations.
+Added: Due to the evolving nature of CMMC and other regulatory requirements, changing customer guidance on data designations, acquisitions, unexpected environments, and the potential for new cybersecurity requirements, there is a risk that we may not meet these new requirements and be unable to bid on certain contracts or be eligible for renewals of existing contracts.
+Added: Government or business decisions could change which areas of the business need to be compliant, which can incur costs or delays in eligibility for the associated contracts.
+Added: Failure to adhere to cybersecurity requirements during the performance of government contracts could also subject us to liability for such non-compliance.
+Added: Additionally, our subcontractors and certain vendors may need to obtain CMMC or other certifications, and we may be negatively impacted if they are not compliant with these requirements.
+Added: Our CIO and CISO / VP of Cybersecurity , each with 20+ years of related experience, are responsible for the day-to-day management of our cybersecurity program and cybersecurity risks.
Our CISO and team are primarily responsible for our overall cybersecurity risk management program and supervise both internal and external resources to identify, protect against, detect, respond to, and recover from cybersecurity risks, threats, and incidents .
−Removed: We have internal Cybersecurity Council which meets monthly to help communicate our enterprise cybersecurity strategy and ensure it is implemented across the business, as well as maintain awareness of events and changes occurring throughout the business.
−Removed: The Cybersecurity Council consists of members from our CIO organization as well as senior leadership from various functional areas of the business.
−Removed: The CISO and VP of Cybersecurity report cybersecurity incidents to members of the company’s senior management, including the Cybersecurity Council, CIO, CEO, and the Board of Directors based on the severity and type of the incident to ensure proper external reporting is completed thoroughly and timely.
+Added: We have monthly meetings of our internal Configuration Control Board to help communicate and manage changes to our enterprise cybersecurity strategy and ensure it is implemented across the business, as well as to maintain awareness of events and changes occurring throughout the business.
+Added: The CISO / VP of Cybersecurity reports cybersecurity incidents to members of the company’s senior management, including the CIO, Chief Executive Officer (“CEO”), and the Board of Directors based on the severity and type of the incident to ensure proper external reporting is completed thoroughly and timely.
Pursuant to its charter, the Cybersecurity Committee of our Board of Directors is responsible for reviewing, discussing, and making recommendations to the full board regarding cybersecurity matters.
−Removed: Our CIO, CISO, and VP of Cybersecurity provide presentations to the Cybersecurity Committee on our cybersecurity program at each of the committee’s regularly scheduled quarterly meetings.
+Added: Our CIO and CISO / VP of Cybersecurity provide presentations to the Cybersecurity Committee on our cybersecurity program at each of the committee’s regularly scheduled quarterly meetings.
These briefings include assessments of the cyber risk and threats landscape, updates on incidents, policies and procedures, and our investments and plans in cybersecurity risk mitigation and governance.
−Removed: The Cybersecurity Committee also meets with members of the Cybersecurity Council to discuss various aspects of our cybersecurity program between regular meetings.
−Removed: All members of the Board of Directors are invited to attend all meetings of the Cybersecurity Committee, and the committee regularly briefs the entire board regarding their oversight of our cybersecurity program.
+Added: The Cybersecurity Committee also meets with the CIO and CISO to discuss various aspects of our cybersecurity program between regular meetings.
+Added: All members of the Board of Directors are invited to attend all meetings of the Cybersecurity Committee, and the committee regularly briefs the entire board regarding its oversight of our cybersecurity program.
Cybersecurity Threats
5 unchanged sentences
As of April 30, 2026, our facilities are primarily leased.
−Removed: Our corporate headquarters are located in Arlington, Virginia where we currently occupy approximately 7,400 square feet under an amended lease agreement expiring in June 2030.
−Removed: Under leases in effect prior to the closing of the BlueHalo acquisition, we also lease (i) a total of approximately 280,000 square feet of space in Simi Valley, California, which leases expire between 2027 and 2030, (ii) approximately 150,000 square feet of space in Moorpark, California, which lease expires in 2027, used for administration and to design, engineer, test and manufacture UAS, and (iii) other facilities in California, Alabama, Kansas, Massachusetts, Florida, Pennsylvania, Minnesota, and Virginia.
+Added: Our corporate headquarters are located in Arlington, Virginia where we currently occupy approximately 7,400 square feet under an amended lease agreement expiring in August 2030.
+Added: We also lease (i) a total of approximately 280,000 square feet of space in Simi Valley, California, which leases expire between 2027 and 2030, (ii) a total of approximately 200,000 square feet of space in Albuquerque, New Mexico, which leases expire between 2028 and 2034, (iii) a total of approximately 150,000 square feet of space in Huntsville, Alabama, which leases expire between 2026 and 2029, and (iv) approximately 150,000 square feet of space in Moorpark, California, for which the lease expires in 2030.
+Added: These locations are used for administration and to design, engineer, test and manufacture, and (v) other facilities in California, Maryland, Florida, Virginia, Pennsylvania, Kansas, Colorado, Minnesota, Oklahoma, Texas and Ohio.
We have international locations in Hampton Bishop, United Kingdom, used for business development and program management support, and Stuttgart, Germany, which facilities are used for administration, research and development, logistics, testing and manufacturing of UGV products.
−Removed: As of April 30, 2025, our business segments as in effect during the year ended on such date (Uncrewed Systems, or “UxS;” Loitering Munitions Systems, or “LMS;” and MacCready Works, or “MW”) had significant operations at the following locations:
−Removed: ● UxS, LMS, and MW:
−Removed: Simi Valley, CA;
−Removed: Moorpark, CA;
+Added: As of April 30, 2026, our business segments of AxS and SCDE had significant operations at the following locations listed alphabetically:
+Added: Centreville, VA;
Huntsville, AL;
Lawrence, KS;
−Removed: Wilmington, MA;
−Removed: Centreville, VA;
−Removed: and Minneapolis, MN.
+Added: Leesburg, VA;
+Added: Moorpark, CA;
Petaluma, CA;
−Removed: Rohnert Park, CA;
−Removed: San Diego, CA;
−Removed: Melbourne, FL;
−Removed: Hampton Bishop, United Kingdom;
−Removed: Stuttgart, Germany and Erie, PA.
−Removed: Arlington, VA, Moorpark, CA and Simi Valley, CA.
−Removed: Additionally in May 2025, we acquired BlueHalo, which has operations in Florida, Pennsylvania, New Mexico, California, Maryland, Virginia, Alabama, and Ohio.
+Added: Pottstown, PA;
+Added: San Luis Obispo, CA;
+Added: Simi Valley, CA;
+Added: Stuttgart, Germany.
+Added: Albuquerque, NM;
+Added: Annapolis Junction, MD;
+Added: Huntsville, AL;
+Added: Germantown, MD.
+Added: Arlington, VA;
+Added: Herndon, VA and Simi Valley, CA.
Legal Proceeding s.
+Added: On May 26, 2026, a securities class action complaint was filed in the U.S.
+Added: District Court for the Eastern District of Virginia by Eric Norrell naming AeroVironment;
+Added: Wahid Nawabi, our President and CEO;
+Added: Kevin McDonnell, our former Executive Vice President and Chief Financial Officer;
+Added: and Mary Clum, President of our Space, Cyber & Directed Energy segment, as defendants.
+Added: See Norell v.
+Added: AeroVironment, Inc., No.
+Added: 1:26-cv-01429 (E.D.
+Added: The complaint asserts violations of Sections 10(b) and 20(a) of the Securities Exchange Act of 1934, as amended, and Rule 10b-5 promulgated thereunder, claiming that the defendants made false and materially misleading statements regarding our work for the U.S.
+Added: Space Force’s Satellite Communication Augmentation Resource (“SCAR”) program.
+Added: The plaintiff seeks to represent a proposed class of all persons who purchased or otherwise acquired our common stock during the period June 25, 2025 through March 10, 2026.
+Added: The complaint seeks a jury trial and unspecified compensatory damages, interest, and attorneys’ fees and other costs.
On August 9, 2021, a former employee filed a class action complaint against AeroVironment in California Superior Court in Los Angeles, California alleging various claims pursuant to the California Labor Code related to wages, meal breaks, overtime, unreimbursed business expenses and other recordkeeping matters.
2 unchanged sentences
The parties participated in a mediation session on May 8, 2025, but did not reach a resolution during the session.
−Removed: On March 29, 2024, a former employee filed a complaint against AeroVironment in the Ventura County Superior Court in California, alleging violations of the California Labor Code related to wages, meal breaks, overtime, unreimbursed business expenses and other recordkeeping matters and seeking penalties recoverable under California Labor Code section 2698, et.
+Added: On March 29, 2024, a former employee filed a complaint against AeroVironment in the Ventura County Superior Court in California, alleging violations of the California Labor Code related to wages, meal breaks, overtime,
+Added: unreimbursed business expenses and other recordkeeping matters and seeking penalties recoverable under California Labor Code section 2698, et.
seq., Private Attorney General Act of 2004 (“PAGA”) and all other remedies available under PAGA.
5 unchanged sentences
The estimated settlement was accrued in our consolidated statements of income(loss) for the year ended April 30, 2025.
+Added: We are currently working with the plaintiff to seek preliminary approval of the settlement.
We are subject to lawsuits, government investigations, audits and other legal proceedings from time to time in the ordinary course of our business.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.