A10 Networks

United States · www.a10networks.com · 28 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 28 sub-vendors.

Insights

Last updated 2026-09-13 · revision 6

28 direct vendors, 289 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

A10 Networks exhibits strong migration readiness, earning a score of 70. This is primarily driven by its highly advanced and flexible internal technology stack. The company extensively utilizes multi-cloud platforms (Amazon Web Services, Microsoft Azure, Google Cloud Platform, Oracle Cloud), container orchestration (Kubernetes, Docker), infrastructure-as-code (HashiCorp Terraform), and RESTful APIs (aXAPI), which are hallmarks of a cloud-native and agile environment. This technical foundation significantly reduces the complexity and effort associated with migrating applications and infrastructure. A10 Networks' stable financial performance and projected growth also suggest it has the resources to fund substantial migration initiatives. However, migration readiness is significantly challenged by a complex and partially unaddressed regulatory environment. The 'Partially Compliant' status for GDPR, particularly concerning cross-border data transfers and the lack of publicly documented Standard Contractual Clauses, introduces friction for migrating EU/EEA data. The 'Assessment Required' status for NIS2 (due to supply chain security requirements from EU customers) and HIPAA (potential Business Associate obligations) means that any migration involving these sectors would require careful compliance planning. The 'Unknown' status for SOC 2 for its cloud services is a notable gap, as SOC 2 reports are often a prerequisite for enterprise cloud adoption. Furthermore, while A10 Networks' on-premises products allow customer-controlled data residency, explicit data residency commitments for its own cloud-delivered services are not publicly disclosed, which could complicate migration strategies for customers with strict data localization requirements. The 'Unknown' vendor lock-in risk, despite the internal tech stack's flexibility, remains a potential hurdle. The conflicting 'Total Vendors: 0' data point makes a precise assessment of vendor lock-in difficult, but the multi-cloud strategy generally mitigates single-vendor dependence.

Compliance

10 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Compliant

A10 Networks has publicly confirmed and documented ISO 27001:2013 certification, with a downloadable certificate available on their official certifications page. The certification scope covers 'the business process of developing, servicing and support of A10's network and security products.' This is strong, verified evidence of compliance with the internationally recognized information security management standard. Risk is Low because: (1) the certification is publicly disclosed with a downloadable certificate; (2) ISO 27001 requires annual surveillance audits and triennial recertification, indicating ongoing compliance management; (3) the scope is directly relevant to A10's core business activities; (4) this certification supports customer trust and regulatory compliance across multiple frameworks.

Evidence: https://www.a10networks.com/products/certifications/, https://www.a10networks.com/wp-content/uploads/A10-ISO27001-2022-Certificate.pdf

FIPS 140-2 — Compliant

A10 Networks has achieved multiple FIPS 140-2 Level 2 certifications validated by NIST's Cryptographic Module Validation Program (CMVP). The most recent active certification (Certificate #4695) covers Thunder 1040, 3350S, 6655S, and 7655S hardware with ACOS software 5.2.1-P5. This is a strong compliance posture for US federal government and defense customers. Risk is Low because the certifications are independently validated by NIST and publicly verifiable.

Evidence: https://www.a10networks.com/products/certifications/, https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4695, https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4358

Common Criteria — Compliant

A10 Networks has achieved Common Criteria certifications for multiple Thunder product lines through both the international Common Criteria Recognition Arrangement (CCRA) and the US National Information Assurance Partnership (NIAP). The most recent certifications cover Thunder 4435, 5840-11, 7445, 7650-11, and 7655 running ACOS 5.2.1-P3. These certifications are independently evaluated by accredited testing laboratories and are required for US government and NATO procurement. Risk is Low due to independently verified certifications.

Evidence: https://www.a10networks.com/products/certifications/, https://www.commoncriteriaportal.org/files/epfiles/st_vid11316-vr.pdf, https://sitdev.niap-ccevs.org/MMO/Product/st_vid11316-vr.pdf

Financials

Three-year financials

Financial Resilience Score: 9/10

A10 Networks demonstrates exceptional financial resilience characterized by a debt-free balance sheet, strong liquidity, and high-margin recurring revenue streams. The company holds ~$195.6M in cash and marketable securities against zero debt, with working capital of $183.7M at year-end 2024. Gross margins consistently hover around 80%, indicative of a software-rich business model, while services revenue (47% of total) provides visibility through a $148.3M deferred revenue base. Operating cash flow of $90.5M in 2024 comfortably covers capital returns including ~$17.8M in dividends and ~$30M in buybacks, with a $44.2M remaining buyback authorization. The company has completed a multi-year profitability transformation, with adjusted EBITDA margin rising from 5.5% in 2019 to ~30% in 2025 and non-GAAP EPS growing ~30x over the same period. Diversification across 7,000+ customers in 24 countries and a shifting mix toward enterprise (43% in 2024, up from 34% in 2022) reduces cyclicality. Risks include meaningful customer concentration (top 10 customers = 38% of revenue; Customer A alone = 15%; one distributor = 20% of revenue and 34% of gross AR), supply chain concentration on Taiwan-based manufacturers (Lanner, AEWIN) with geopolitical exposure, and lumpy service provider capex cycles as demonstrated by the 2023 revenue decline. Competition from much larger vendors (F5, Cisco, Fortinet, Cloudflare) and a still-present accumulated deficit of $40.3M temper the otherwise strong profile.

Key strengths: Zero debt with ~$195.6M cash and marketable securities, ~80% gross margins indicating software-rich model, Strong operating cash flow of $90.5M in 2024, Recurring services revenue at 47% of total with $148.3M deferred revenue backlog, Consistent capital returns: quarterly dividend plus $50M buyback authorization, Diversified base of 7,000+ customers across 24 countries, Adjusted EBITDA margin expanded from 5.5% (2019) to ~30% (2025), Strong IP portfolio: 210 US patents + 78 overseas patents

Risk factors: Customer concentration: top 10 customers = 38% of revenue; Customer A = 15%, Distribution concentration: one partner = 20% of revenue, 34% of gross AR, Supply chain concentration on Taiwan-based manufacturers (geopolitical/tariff risk), Lumpy service provider capex cycles (evident in 2023 revenue decline), Intense competition from larger vendors: F5, Cisco, Fortinet, Cloudflare, Radware, FX exposure primarily to Japanese Yen, Historical accumulated deficit of $40.3M — sustained profitability only recently achieved, Cybersecurity risk highlighted by January 2023 corporate IT incident

Revenue by geography

Revenue by product/service

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report