Amazon Web Services (aws)
United States · owned by Amazon.com, Inc. (United States) · aws.amazon.com · 57 vendors
Amazon Web Services (AWS) is the world's most comprehensive and broadly adopted cloud platform, offering over 200 fully featured services from data centers globally. AWS provides scalable, reliable, and inexpensive cloud computing infrastructure including compute power, storage, databases, networking, analytics, machine learning, and more. It serves millions of customers ranging from startups and enterprises to government agencies worldwide.
Resilience scores
- Digital Sovereignty: 75
- Digital Resilience: 10
- Financial Resilience: 9
Disruption prediction
Amazon Web Services (aws) has a 78% probability of disruption in the next 6 months.
All systems operational (last checked 2026-09-18 14:55 UTC)
25 of Amazon Web Services (aws)'s 57 vendors monitored for disruptions.
Technology vendors
- Adobe Inc. — Technology — United States
- Veeam Software Group GmbH — Technology — United States
- Zscaler, Inc. — Cybersecurity — United States
- and 55 more
Services catalogue
189 services in catalogue across 7 categories; runs on 57 sub-vendors.
- OpenSearch Service
- Advertising
- ScalarDL
Insights
Last updated 2026-07-22 · revision 26
57 direct vendors, 356 subvendors
Direct vendors by controlling owner country (sample)
- Australia: 1
- Czech Republic: 1
- Germany: 1
Subvendors by controlling owner country (sample)
- Poland: 1
- Australia: 3
- Moldova: 1
Migration Readiness: 10/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Amazon Web Services (AWS) exhibits extremely high migration readiness, both in terms of its internal agility and its comprehensive support for customer migrations. The company's internal tech stack is the epitome of cloud-native architecture, heavily utilizing containerization (Kubernetes, Docker, ECS, EKS, Fargate), serverless computing (Lambda), microservices, and custom silicon (Graviton, Trainium, Inferentia). This advanced and agile internal environment allows AWS to rapidly innovate and adapt its platform, directly benefiting customer migration efforts by providing a robust and modern target environment. AWS's extensive regulatory compliance (GDPR, HIPAA, SOC 2, ISO 27001, FedRAMP, PCI DSS, CCPA/CPRA, CSA STAR, ISO 22301) significantly simplifies the compliance burden for customers undertaking migrations, as AWS provides the foundational compliance for its infrastructure. Its proactive engagement with evolving regulations like NIS2, DORA, and the EU AI Act ensures ongoing readiness. Data residency is a core strength, with AWS operating 39 Regions and 123 Availability Zones globally, offering explicit guarantees against data movement without consent. This includes dedicated EU, US GovCloud, and numerous country-specific regions (e.g., Germany, France, China, India, Australia, Canada, Brazil), along with tools like Service Control Policies (SCPs) and AWS Control Tower, enabling customers to meet even the most stringent data localization requirements during migration. Financially, AWS's strong and consistent revenue growth provides ample resources for continuous investment in infrastructure, R&D, and migration support services. The data indicating 'Total Vendors: 0' for AWS implies that the company itself is not constrained by external vendor lock-in, allowing it maximum flexibility to evolve its services and support complex migration scenarios without external dependencies. While AWS's comprehensive ecosystem can create lock-in for customers migrating *away* from AWS, this assessment focuses on *AWS's* readiness to facilitate and adapt to migration needs, which is exceptionally high.
Compliance
15 in-scope frameworks identified; showing 3.
SOX — Compliant
Amazon.com, Inc. (AWS's parent company) is a publicly traded company on NASDAQ and is subject to SOX requirements for financial reporting controls. AWS's infrastructure and services are subject to SOX-relevant IT General Controls (ITGCs). Risk is Medium because: (1) SOX Section 404 requires management assessment and external auditor attestation of internal controls over financial reporting; (2) AWS's cloud services are used by many SOX-regulated companies, creating indirect SOX relevance; (3) Amazon's own SOX compliance is subject to annual external audit by Ernst & Young LLP; (4) Any material weakness in AWS's financial reporting controls could have significant consequences.
Evidence: https://aws.amazon.com/compliance/soc-faqs/, https://aws.amazon.com/artifact/, https://ir.aboutamazon.com/sec-filings/annual-reports/, https://aws.amazon.com/compliance/programs/
SOC 2 (source) — Compliant
AWS holds SOC 2 Type II reports covering Security, Availability, Confidentiality, and Privacy Trust Service Criteria. These reports are issued by independent third-party auditors (Big Four accounting firms) on a regular basis (typically semi-annual or annual). Risk is Low because: (1) AWS has maintained continuous SOC 2 compliance for many years with no material exceptions reported; (2) SOC 2 Type II (not just Type I) demonstrates operating effectiveness over a period of time, not just design; (3) AWS's scale and investment in security controls make SOC 2 compliance highly reliable; (4) Reports are available through AWS Artifact for customer due diligence. The primary residual risk is the shared responsibility model — customers must implement their own controls for their applications.
Evidence: https://aws.amazon.com/compliance/soc-faqs/, https://aws.amazon.com/artifact/, https://aws.amazon.com/compliance/programs/, https://aws.amazon.com/compliance/soc-3-report/
PDPA — Compliant
AWS operates data centers and serves customers across Asia-Pacific, Latin America, and other regions subject to national data protection laws. AWS has implemented compliance programs for major national privacy laws including Singapore PDPA, Australia Privacy Act, Brazil LGPD, Japan APPI, South Korea PIPA, and India's Digital Personal Data Protection Act (DPDP). Risk is Medium because: (1) These laws vary significantly in requirements and enforcement; (2) Some laws (e.g., India DPDP, South Korea PIPA) have strict data localization or cross-border transfer requirements; (3) Enforcement is increasing globally; (4) AWS's compliance posture varies by jurisdiction and law.
Evidence: https://aws.amazon.com/compliance/data-privacy-faq/, https://aws.amazon.com/compliance/apec/, https://aws.amazon.com/compliance/programs/, https://aws.amazon.com/compliance/australia-irap/
Financials
Three-year financials
- 2024: revenue USD 107,556M, EBIT USD 39,834M
- 2023: revenue USD 90,757M, EBIT USD 24,631M
- 2022: revenue USD 80,096M, EBIT USD 22,841M
Financial Resilience Score: 9/10
AWS demonstrates exceptional financial resilience as the dominant global cloud infrastructure provider, with FY2024 revenue of $107.6B and operating income of $39.8B representing a 37% operating margin — extraordinarily high for an infrastructure business. Revenue growth reaccelerated to 18.5% in 2024 after a slowdown to 13.3% in 2023, and operating income surged 61.7% year-over-year, reflecting strong AI-driven demand, favorable useful-life adjustments on servers, and cost discipline. AWS benefits from significant structural advantages: it is the #1 hyperscaler globally with roughly 30% market share, holds over $150B in remaining performance obligations (multi-year enterprise contracts) providing revenue visibility, and is backed by Amazon's consolidated balance sheet (~$285.9B equity in FY2024) with substantial cash reserves and free cash flow. This allows AWS to fund heavy capex ($100B+ guided for 2025) without external financing, while maintaining pricing power through a diversified customer base across industries and geographies. Key risks include accelerating capital intensity tied to AI infrastructure buildout (margin sustainability depends on utilization), intensifying competition from Microsoft/OpenAI, Google, Oracle, and specialty GPU clouds, regulatory scrutiny in the US, UK, and EU, and heavy dependency on Nvidia GPUs. Nonetheless, the combination of dominant market position, high margins, contracted backlog, and parent-company strength support a very high resilience rating.
Key strengths: Dominant #1 position in global cloud infrastructure (~30% market share), 37% operating margin in FY2024, exceptionally high for infrastructure business, Remaining performance obligations exceeding $150B providing revenue visibility, Backed by Amazon consolidated equity of ~$285.9B and strong free cash flow, Diversified customer base across industries, governments, and geographies, Strong reacceleration of growth to 18.5% in FY2024 driven by generative AI demand
Risk factors: Accelerating capital intensity with 2025 capex guided over $100B, Intensifying AI competition from Microsoft/OpenAI, Google, Oracle, and GPU-specialty clouds, Regulatory scrutiny from FTC (US), CMA (UK), and EU on cloud market practices, Heavy dependency on Nvidia GPUs; in-house Trainium/Inferentia chips unproven at scale, Customer concentration on AI hyperscale workloads (e.g., Anthropic), FX exposure on 30%+ international sales
Revenue by product/service
- Compute (EC2 and derivatives): 45%
- Networking, security, analytics, ML/AI and other: 28%
- Storage (S3, EBS, Glacier): 15%
- Databases (RDS, DynamoDB, Aurora, Redshift): 12%
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.