Alstom

France · owned by Independent (France) · www.alstom.com · 16 vendors

Alstom SA is a French multinational company specializing in rail transport systems. It designs, manufactures, and services a comprehensive range of products including high-speed trains, metros, trams, and monorails. The company also provides signaling, infrastructure, and digital mobility solutions for the railway sector globally.

Resilience scores

Disruption prediction

Alstom has an estimated 40% probability of disruption in the next 6 months.

9 of Alstom's 16 vendors monitored for disruptions.

Technology vendors

Services catalogue

2 services in catalogue across 1 category; runs on 16 sub-vendors.

Insights

Last updated 2026-09-12 · revision 1

16 direct vendors, 224 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 3/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Alstom's migration readiness is assessed as low, primarily due to significant reliance on complex, deeply integrated legacy enterprise systems such as SAP ERP, Siemens PLM/Teamcenter, and Dassault Systèmes 3DEXPERIENCE (CATIA). These systems typically involve substantial migration challenges and potential vendor lock-in. A major impediment to cloud-native migration is the extensive use of 'Embedded Safety-Critical Software (SIL 4)', which requires extremely rigorous validation and certification, making refactoring or moving these core operational components to generic cloud environments exceptionally difficult and costly. While Alstom does utilize modern technologies like Microsoft Azure and cloud-based IoT platforms, along with Python, Java, and Linux, indicating some existing cloud adoption and development capabilities, these are likely peripheral to the core safety-critical and legacy enterprise systems. The absence of specific data on regulatory compliance requirements, data residency constraints, and the company's financial capacity to fund a large-scale migration further introduces significant uncertainty and risk to any modernization efforts. The 'Vendor Lock-in Risk' is explicitly unknown, but the nature of the critical enterprise software implies a high degree of dependency on these specific vendors.

Compliance

7 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

As a supplier to the critical transport sector, customers and regulators expect robust information security management. ISO 27001 is the globally recognized standard for an Information Security Management System (ISMS).

While not legally mandated, ISO 27001 certification is a key customer expectation in the critical infrastructure sector. Lacking certification could be a competitive disadvantage and may indicate gaps in information security management, increasing operational and data breach risks.

Evidence: https://securitymea.com/2023/05/22/alstom-addresses-the-entire-rail-cybersecurity-lifecycle/, https://www.alstom.com/press-releases-news/2022/9/rail-cybersecurity-flipside-digitalisation, https://www.alstom.com/press-releases-news/2024/3/towards-first-railway-cybersecurity-international-standard-why-standards-are-important-secure-railways, https://www.alstom.com/cybersecurity-safe-secure-mobility

ECM Regulation — Compliant

Alstom provides maintenance services for railway vehicles in the European Union. Regulation (EU) 2019/779 mandates that any such entity must be certified as an ECM to ensure safe operation.

Failure to comply with Entity in Charge of Maintenance (ECM) regulations would prevent Alstom from providing maintenance services for rolling stock in the EU, a core part of its business. This would result in direct revenue loss and breach of contract.

Evidence: https://www.alstom.com/solutions/services/flexcare-perform-rail-maintenance-services-all-types-assets, https://jobsearch.alstom.com/job/Savigliano-Project-Maintenance-Engineering-Manager-21/1393321733/

Cyber Resilience Act (source) — Partially Compliant

Alstom manufactures and sells numerous products with digital elements within the EU, such as its Agate train control systems. The CRA applies directly to manufacturers of such products, placing responsibility on them for the product's security.

The CRA will impose lifecycle security requirements on Alstom's products with digital elements (e.g., signalling, control systems). Non-compliance could halt sales in the EU and lead to significant fines. The complexity of its supply chain adds risk.

Evidence: https://www.alstom.com/solutions/components/agate-train-control-and-information-systems-enabling-digital-train, https://www.alstom.com/trackside-signalling-equipment-digital-standards-rail-and-metro-networks, https://www.alstom.com/stories/why-rail-cybersecurity-requires-different-security-model, https://www.globalrailwayreview.com/webinars/the-cyber-resilience-act-implications-for-the-global-rail-industry/384349.article, https://www.facebook.com/ALSTOM/videos/we-are-gearing-up-for-cyber-senate-conferences-in-london-tomorrowunderstanding-t/9484495881588604/, https://www.alstom.com/cybersecurity

Financials

Three-year financials

Financial Resilience Score: 7/10

Alstom has substantially strengthened its financial position over the past two fiscal years following a difficult FY 2023/24 that triggered a €1 bn rights issue and non-core disposals. Net debt has been reduced to just €404 m from ~€3.0 bn pre-capital raise, and the company returned to positive free cash flow (€336 m in FY 2025/26, €502 m in FY 2024/25) and rebuilt net profitability (€324 m Group share in FY 2025/26). Liquidity is strong with €2.3 bn cash plus €4.25 bn in undrawn credit facilities, and the company maintains investment grade ratings. The order backlog of €104.4 bn (5.4x annual sales) provides multi-year revenue visibility, and the gross margin in backlog improved 20 bps to 18.0%, supporting management's medium-term ambition of 8–10% adjusted EBIT margin. Structural tailwinds from rail decarbonisation and public infrastructure investment underpin demand, and record FY 2025/26 order intake of €27.6 bn (book-to-bill 1.4) confirms commercial momentum. However, resilience is tempered by execution risk on large fixed-price rolling-stock contracts, which caused ~60 bps of margin dilution in FY 2025/26 and kept adjusted EBIT margin (6.1%) well below peers like Siemens Mobility. Working capital volatility is significant, with H1 FY 2026/27 guided to €(1.5) bn FCF consumption. Bombardier Transportation integration legacy issues (€236 m PPA/impairment charges in FY 2025/26) continue to weigh, and 40%+ non-European exposure creates FX risk.

Key strengths: Record €104.4 bn backlog providing 5.4x sales visibility, Strong liquidity: €2.3 bn cash + €4.25 bn undrawn credit facilities, Net debt reduced to €404 m post 2024 rights issue and disposals, Return to positive free cash flow (€336 m in FY 2025/26), Record FY 2025/26 order intake of €27.6 bn (book-to-bill 1.4), Investment grade credit rating, Diversified geographic footprint across 61 countries, Recurring Services franchise (24% of sales) with higher margins, Structural tailwinds from rail decarbonisation and public infrastructure

Risk factors: Execution risk on large rolling-stock projects (60 bps margin dilution in FY 2025/26), Long-cycle fixed-price contracts vulnerable to inflation and cost overruns, Working capital volatility with H1 FY 2026/27 guided to €(1.5) bn FCF consumption, Adjusted EBIT margin (6.1%) below peers like Siemens Mobility, Bombardier Transportation integration legacy charges (€236 m PPA/impairment in FY 2025/26), FX exposure with 40%+ sales outside Europe (20 bps margin impact in FY 2025/26), Competition from CRRC, Stadler, CAF, Hitachi, Capital Markets Day pushed to early 2027 delays strategic clarity

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report