AMS-IX

Netherlands · www.ams-ix.net · 46 vendors

AMS-IX (Amsterdam Internet Exchange) is a neutral, member-based association that operates multiple interconnection platforms worldwide. It enables internet service providers, telecom companies, and cloud providers to efficiently, securely, and cost-effectively exchange global IP traffic. This facilitates low latency and engaging online experiences for end-users.

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 46 sub-vendors.

Insights

Last updated 2026-05-19 · revision 7

46 direct vendors, 350 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

AMS-IX exhibits medium migration readiness. The company's internal tech stack provides a good foundation for modernization and platform shifts, leveraging virtualization (VMware/KVM), containerization (LXC), and extensive automation through Zero-Touch Provisioning, REST APIs, and JSON-based configuration. Its consistent financial growth indicates the ability to fund migration initiatives. However, significant challenges exist. The core business as an Internet Exchange Point operator relies on specialized physical infrastructure (e.g., Nokia SR Linux, DWDM, Photonic Cross Connects), which inherently limits direct 'cloud-native' migration to public cloud providers. The regulatory environment presents major hurdles; GDPR and NIS2 compliance are 'Assessment Required' with 'High risk' and no audit evidence, meaning any migration would require substantial effort to ensure compliance with these and other local data protection laws across its 13 operational countries. Complex data residency requirements, particularly for EU residents' personal data and potential NIS2 restrictions on services from high-risk third countries, add significant complexity to cross-border migrations. The 'Vendor Lock-in Risk' is 'Unknown,' which is a critical information gap, but the specialized nature of their network hardware implies a degree of vendor dependency that could complicate transitions. While technically capable of modernization, the external regulatory and data residency complexities, combined with unknown vendor lock-in, significantly temper overall migration readiness.

Compliance

4 in-scope frameworks identified; showing 3.

GDPR (source) — Compliant

AMS-IX is headquartered in the Netherlands (EU) and processes personal data of customers, employees, and website visitors. Their privacy statement explicitly references GDPR compliance and includes all required elements (data subject rights, lawful basis, retention periods, etc.). As a B2B telecommunications infrastructure provider, they have lower personal data processing volumes than consumer-facing companies, reducing risk. However, non-compliance could result in significant fines up to 4% of annual turnover.

Evidence: https://www.ams-ix.net/ams/documentation/privacy-statement

ISO 27001 (source) — Assessment Required

As a critical telecommunications infrastructure provider handling sensitive network routing information and serving major ISPs and cloud providers, ISO 27001 certification would be expected for information security management. While not legally required, it's often a customer requirement for critical infrastructure providers. The risk is moderate as it affects customer confidence and competitive positioning rather than regulatory compliance.

SOC 2 (source) — Assessment Required

As a critical infrastructure provider serving cloud providers, ISPs, and telecom companies globally, SOC2 compliance would be expected by enterprise customers for security and availability assurance. While not legally mandated, lack of SOC2 could impact customer trust and competitive positioning. The risk is moderate as it's primarily a commercial rather than regulatory requirement.

Financials

Financial Resilience Score: 8/10

AMS-IX demonstrates strong financial resilience rooted in its not-for-profit, association-owned structure and highly recurring revenue model. Port fees and membership fees from 800+ connected networks (ISPs, hyperscalers like Google, Meta, Netflix, Microsoft, Amazon, and CDNs) provide predictable cash flow with no single-customer concentration risk. As one of the top global interconnection hubs within the FLAP-D cluster (Frankfurt, London, Amsterdam, Paris, Dublin), AMS-IX benefits from strong network effects that reinforce member retention and switching costs. The cost-recovery pricing model reduces pressure to take on debt or pursue risky expansion, with equity conservatively built from retained surpluses. The organization has operated since 1997 with a strong technical reputation and very high uptime. However, structural headwinds exist: hyperscalers increasingly bypass public IXPs via private network interconnects (PNIs), competing European IXPs (DE-CIX, LINX, France-IX) exert price pressure on per-Gbps rates, and Dutch energy cost volatility since 2022 affects operating costs. Foreign ventures have had mixed results historically (Hong Kong operation discontinued). Revenue growth has historically lagged traffic growth in low-to-mid single digits due to the volume-up/price-down dynamic of the IXP industry. Note: Specific financial figures could not be verified in this research session as web access was blocked. Historical pre-2022 reports suggested annual revenue in the range of €15–20 million range, but these should not be treated as current figures.

Key strengths: Recurring revenue model from port and membership fees, Diversified customer base of 800+ networks with no single-customer dominance, Strategic position in FLAP-D interconnection hub, Not-for-profit/association ownership structure reducing financial risk, Strong network effects and high switching costs, Long operating history since 1997 with high uptime reputation

Risk factors: Direct peering/private network interconnects (PNIs) by hyperscalers bypassing public IXPs, Price compression from competing European IXPs (DE-CIX, LINX, France-IX), Volatile Dutch electricity prices since 2022 affecting operating costs, Mixed profitability of international ventures (Hong Kong discontinued), Regulatory compliance costs from NIS2 and EU critical infrastructure rules, Revenue growth lagging traffic growth due to per-Gbps price declines

Revenue by geography

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report