A-LIGN
United States · a-lign.com · 36 vendors
Resilience scores
- Digital Sovereignty: 81
- Digital Resilience: 9
- Financial Resilience: 6
Technology vendors
- AuditBoard — Technology — United States
- Click Guardian — United Kingdom
- Stripe, Inc. — Financial Services — United States
- and 33 more
Services catalogue
2 services in catalogue across 2 categories; runs on 36 sub-vendors.
- Compliance Certification
- Insurance Platform Enhancement
Insights
Last updated 2026-08-14 · revision 1
36 direct vendors, 289 subvendors
Direct vendors by controlling owner country (sample)
- Sweden: 1
- France: 1
- Australia: 1
Subvendors by controlling owner country (sample)
- Germany: 6
- Unknown: 2
- Bangladesh: 2
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
A-LIGN's migration readiness is moderate, primarily due to existing cloud adoption but also significant unknowns. A key strength is the current use of Google Cloud Platform, which provides a foundation for cloud migration. Their extensive expertise in complex regulatory frameworks (e.g., FedRAMP, GDPR, HIPAA, ISO standards) suggests they possess the internal knowledge to navigate compliance aspects during a migration. The geographic diversity of their vendor base (4 countries) could offer some flexibility in vendor selection or service migration. However, several critical unknowns significantly impact readiness. The specific architecture of their applications (e.g., cloud-native, containerized, microservices) is not detailed, making it difficult to assess the complexity of application refactoring or re-platforming. The absence of 'Data Residency Requirements' is a major gap, as these requirements often dictate architectural choices and vendor selection. Financial stability (revenue concentration, growth history) is unknown, which impacts the ability to fund a potentially large-scale migration. The 'Total Vendors: 0' data point is contradictory to 'Total Services: 30' and 'Vendor HQ Countries'. Assuming vendor relationships exist, the lack of a distinct vendor count makes it impossible to accurately assess vendor lock-in risk, which can be a significant impediment if many services are tied to a few critical vendors. The presence of 'Microsoft Office Suite', 'Microsoft Teams', and 'Microsoft SharePoint' in their internal tech stack suggests potential dependencies on traditional enterprise software that might require specific migration strategies.
Compliance
11 in-scope frameworks identified; showing 3.
CPRA — Compliant
A-LIGN has a comprehensive California Consumer Privacy Statement as an attachment to its Privacy Policy (effective January 1, 2023, covering CCPA as amended by CPRA). The company explicitly addresses all CCPA/CPRA rights (access, correction, deletion, opt-out of sale/sharing), provides a dedicated contact mechanism (email and phone 1-888-702-5446), and discloses categories of personal information collected, used, and shared. As a US-based company with California customers and website visitors, CCPA/CPRA applies. Risk is Low because A-LIGN has implemented a detailed, publicly available CCPA compliance program and is itself a compliance services provider.
Evidence: https://www.a-lign.com/privacy-policy, https://www.a-lign.com/service/ccpa-cpra, https://www.a-lign.com/cookie-policy
NIS2 (source) — Assessment Required
A-LIGN has significant EU operations (offices in Bulgaria and Ireland, both EU member states) and operates as a digital/ICT services provider — a sector that falls within NIS2's scope for 'Important Entities' under the 'digital providers' and 'ICT service management' categories. A-LIGN provides cybersecurity audit, compliance, and managed security services to organizations across the EU, and operates its A-SCEND platform as a cloud-based SaaS tool. NIS2 Directive (EU 2022/2555) covers 'managed security service providers' explicitly as Important Entities (Annex II). A-LIGN's EU entity size (Bulgaria + Ireland offices) relative to the 50-employee / €10M turnover threshold is not publicly confirmed, creating some uncertainty. However, given the company's global scale (6,400+ clients, 36,000+ audits), it is highly likely the EU entities exceed these thresholds. Risk is Medium because NIS2 non-compliance for in-scope entities carries significant penalties (up to €7M or 1.4% of global annual turnover for Important Entities), and the sector match is strong, but formal NIS2 assessment status has not been publicly confirmed.
Evidence: https://www.a-lign.com/service/nis2, https://www.a-lign.com/about, https://trust.a-lign.com/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555
PCI DSS (source) — Assessment Required
A-LIGN is a PCI Qualified Security Assessor Company (QSAC), confirmed on its About page, meaning it is authorized to conduct PCI DSS assessments for clients. As a QSAC, A-LIGN is subject to PCI SSC (Payment Card Industry Security Standards Council) oversight and must maintain its own compliance with PCI DSS requirements to the extent it handles cardholder data. A-LIGN's Privacy Policy mentions collection of credit card numbers for payment processing, which would trigger PCI DSS scope. Risk is Low because A-LIGN's role as a QSAC requires demonstrated security competence, and its existing SOC 2 and ISO 27001 certifications provide strong underlying controls. However, specific PCI DSS compliance status for A-LIGN's own cardholder data environment has not been publicly confirmed.
Evidence: https://www.a-lign.com/about, https://www.a-lign.com/service/pci-dss, https://www.a-lign.com/service/pci-ssf
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
A-LIGN demonstrates solid qualitative financial resilience despite the absence of public financial disclosures. The company holds category leadership in high-demand cybersecurity compliance niches including being the #1 SOC 2 issuer globally, a Top 3 FedRAMP 3PAO, an accredited C3PAO for CMMC, and an early accredited body for ISO 42001. These positions are protected by regulatory accreditations, qualified auditor backlogs, and reputational moats that are difficult to displace. The business model generates recurring, sticky revenue since audits like SOC 2 Type 2, ISO 27001, and FedRAMP are annual/continuous, and the A-SCEND platform increases switching costs through evidence and workpaper reuse. Regulatory tailwinds provide additional resilience, with CMMC rollout in the US defense supply chain, EU NIS2, DORA, and ISO 42001 for AI governance all expanding the addressable market. PE sponsorship from Warburg Pincus (majority investment November 2021, reportedly ~$260M+) and now Hg provides access to capital for M&A and technology investment. Scale indicators include 6,400+ clients, 36,000+ cumulative audits, and 96% client satisfaction. However, resilience is constrained by opacity around leverage and covenants typical of PE-backed structures, a people-intensive delivery model exposed to cybersecurity wage inflation (evidenced by reported 2023-2024 layoffs), competitive pressure from Big 4, Coalfire, Schellman, and compliance-automation SaaS vendors like Vanta, Drata, and Secureframe, and heavy client concentration in the tech/SaaS sector correlating revenue with tech IT budgets.
Key strengths: #1 SOC 2 issuer globally with 17,500+ SOC assessments completed, Top 3 FedRAMP 3PAO and accredited C3PAO for CMMC, Recurring, sticky revenue from annual audit cycles, A-SCEND SaaS platform increases switching costs, Multi-framework cross-sell across SOC 2, ISO, HITRUST, PCI, FedRAMP, Regulatory tailwinds (CMMC, NIS2, DORA, ISO 42001), PE backing from Warburg Pincus and Hg, 6,400+ active clients and 36,000+ cumulative audits, Dual-accredited (ANAB and UKAS) for ISO 27001, Early accredited body for ISO 42001 (AI governance)
Risk factors: Private, opaque balance sheet with no disclosed leverage or covenants, PE ownership often implies leverage and interest-rate sensitivity, People-intensive delivery model exposed to cybersecurity wage inflation, Reported 2023-2024 layoffs signal margin pressure and utilization risk, Competitive intensity from Big 4 (Deloitte, EY), Coalfire, Schellman, Disintermediation risk from compliance-automation SaaS (Vanta, Drata, Secureframe), Accreditation risk (PCAOB, ANAB, UKAS, FedRAMP 3PAO, C3PAO), Heavy client concentration in tech/SaaS sector
Revenue by geography
- EMEA: 0%
- United States: 0%
- Other (India, Panama delivery centers): 0%
Revenue by product/service
- HITRUST: 0%
- A-SCEND platform: 0%
- PCI DSS / PCI SSF: 0%
- SOC 1 and SOC 2 assessments: 0%
- Privacy (GDPR, CCPA/CPRA) and other add-ons: 0%
- Penetration testing and cybersecurity services: 0%
- Federal assessments (FedRAMP, CMMC, FISMA, NIST 800-171): 0%
- ISO certifications (27001, 27701, 22301, 42001, 9001, 14001, 45001): 0%
Workforce by country
- India: 0
- Panama: 0
- Ireland: 0
- Bulgaria: 0
- United States: 0
- United Kingdom: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.