Brightly Software
United States · www.brightlysoftware.com · 26 vendors
Resilience scores
- Digital Sovereignty: 23
- Digital Resilience: 8
- Financial Resilience: 9
Technology vendors
- Acquia — Technology — United States
- Adobe Inc. — Technology — United States
- Xpansiv CBL Holding Group — United States
- and 23 more
Services catalogue
1 service in catalogue across 1 category; runs on 26 sub-vendors.
- Asset Essentials
Insights
Last updated 2026-08-14 · revision 1
26 direct vendors, 313 subvendors
Direct vendors by controlling owner country (sample)
- Belgium: 1
- Australia: 1
- United Kingdom: 2
Subvendors by controlling owner country (sample)
- Czech Republic: 1
- Austria: 1
- Switzerland: 1
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Brightly Software exhibits high migration readiness primarily because it is already operating as a 'Cloud-based SaaS infrastructure' with 'multi-region deployment: US, UK, Australia'. This indicates a significant portion of any 'migration' to modern cloud environments has already been completed. Its 'Internal Tech Stack' and 'Key Technologies' highlight a modern foundation, including 'Cloud-based SaaS delivery', 'IoT sensor integration platform', and 'AI for maintenance', suggesting an architecture that is likely adaptable and leverages cloud-native principles. The experience with 'GIS / Mapping integration' and 'IoT sensor integration platform' across its products further demonstrates capability in integrating complex, data-intensive services within a cloud framework. The assessment is constrained by missing information. There is 'No data' on specific 'Regulatory Environment' or 'Data Residency Requirements', which could introduce complexities for future migrations or expansions. 'Financial Stability' data is also absent, making it difficult to assess the company's capacity to fund significant migration efforts. The 'Vendor Lock-in Risk' is 'Unknown', and while 'Vendor Geographic Diversity' is present, the precise number of unique vendors for its 'Total Services: 9' is not clear (given 'Total Vendors: 0' is contradictory). A higher number of unique vendors or significant reliance on a few could impact the complexity and cost of migrating away from specific services or platforms. The explicit mention of containerization or microservices architecture is also absent, though often implied by modern SaaS operations.
Compliance
10 in-scope frameworks identified; showing 3.
FedRAMP — Assessment Required
Brightly Software explicitly serves US government clients (counties, municipalities, federal agencies) with its Government industry vertical. FedRAMP authorization is required for cloud service providers (CSPs) offering services to US federal agencies. Risk is MEDIUM because: (1) Brightly serves government clients but primarily at state/local level (municipalities, counties) rather than federal agencies; (2) FedRAMP is mandatory only for federal agency cloud deployments; (3) state and local government clients may require StateRAMP or equivalent; (4) if Brightly serves any federal agencies, FedRAMP authorization would be required; (5) lack of FedRAMP authorization could limit Brightly's ability to expand into federal government market.
Evidence: https://www.brightlysoftware.com/industries/government, https://www.brightlysoftware.com/success-stories/city-asheville-relies-brightly-products-manage-facility-maintenance-make, https://marketplace.fedramp.gov/
GDPR (source) — Assessment Required
Brightly Software has confirmed physical operations in the United Kingdom (Chatham, ME4 4TZ office) and serves clients globally including in the EU/EEA. As a cloud-based SaaS provider with 12,000+ clients and 4.6M users worldwide, Brightly almost certainly processes personal data of EU/EEA residents (employee data, client contact data, end-user data). The company's Privacy Notice is hosted on the Siemens global privacy notice page (siemens.com), suggesting reliance on Siemens' GDPR framework rather than a standalone Brightly GDPR compliance program. Risk is HIGH because: (1) UK GDPR applies directly due to UK office; (2) EU GDPR likely applies due to global client base and potential EU clients; (3) as a data processor for clients in regulated industries (healthcare, government), any GDPR breach could trigger significant fines up to €20M or 4% of global annual turnover; (4) Siemens as parent company is subject to GDPR enforcement across its entire group. Non-compliance consequences are severe given Siemens' global profile and regulatory scrutiny.
Evidence: https://www.brightlysoftware.com/about, https://www.siemens.com/global/en/general/privacy-notice.html, https://www.brightlysoftware.com/cookie-notice, https://trust.brightlysoftware.com/, https://www.brightlysoftware.com/en-gb
ISAE 3000 (source) — Assessment Required
ISAE 3000 is an international assurance standard used for non-financial assurance engagements, commonly applied in the context of SOC 2 reports for non-US entities (where ISAE 3402 is used for service organization controls, analogous to SOC 1). For Brightly Software, ISAE 3000/3402 could be relevant for its UK and Australian operations where clients may request assurance reports under international standards rather than US AICPA SOC 2. Risk is LOW because: (1) ISAE 3000 is not a regulatory requirement but a voluntary assurance framework; (2) Brightly's primary compliance focus appears to be SOC 2 (US standard); (3) no evidence of ISAE 3000 engagements found; (4) penalties for non-compliance are market-driven (contract loss) rather than regulatory. The low risk reflects the voluntary nature of this framework and the availability of SOC 2 as an alternative.
Evidence: https://trust.brightlysoftware.com/, https://www.brightlysoftware.com/en-gb, https://www.brightlysoftware.com/en-au
Financials
Three-year financials
- 2025:
- 2024:
- 2023:
Financial Resilience Score: 9/10
Brightly Software's financial resilience is effectively that of its parent, Siemens AG, one of the world's largest industrial conglomerates with approximately €75 billion in FY2024 revenue and an investment-grade balance sheet. Since being acquired by Siemens in 2022 for approximately US$1.575 billion, Brightly operates as a wholly-owned subsidiary within Siemens Smart Infrastructure, effectively eliminating financing or going-concern risk at the entity level. The business itself is built on a highly recurring SaaS revenue model with multi-year subscriptions and sticky public-sector customers in education, government, and healthcare, resulting in low churn. At the time of acquisition, Brightly reported approximately US$180 million in revenue with about 25% year-over-year growth, indicating a healthy growth trajectory. The customer base of ~12,000 clients and ~4.6 million users is highly diversified, with no single client material to revenue. However, the lack of standalone financial disclosure post-acquisition limits external visibility into margins, cash conversion, and profitability at the Brightly business unit level. Public-sector budget exposure (K-12 schools, municipalities) creates some sensitivity to tax revenues and federal grant cycles (e.g., ESSER funds tail-off).
Key strengths: Backed by Siemens AG with investment-grade balance sheet (~€75B revenue FY2024), Highly recurring SaaS revenue model with multi-year subscriptions, Diversified client base of ~12,000 customers across multiple verticals, Sticky vertical software with low churn due to operational disruption of switching, Strategic integration with Siemens Xcelerator and Building X platforms, Strong ~25% YoY growth at time of Siemens acquisition
Risk factors: Competitive market with IBM Maximo, Infor EAM, IFS, Trimble, Accruent, and others, Public-sector budget exposure sensitive to tax revenues and federal grants, Integration and rebranding risk transitioning to 'Siemens Asset Management Software', FX exposure across USD, GBP, and AUD via Confirm (UK) and Assetic (Australia), Opacity due to lack of standalone financial disclosure post-acquisition
Revenue by geography
- United States: 70%
- United Kingdom & Europe: 13%
- Australia / New Zealand: 10%
- Rest of World (Canada, other): 7%
Revenue by product/service
- Asset Essentials / Dude Solutions (Education & Government CMMS): 45%
- TheWorxHub (Healthcare & Senior Living): 20%
- Confirm (UK Public Infrastructure EAM): 15%
- Assetic / Predictor / Origin (Capital Planning): 12%
- Energy Manager / Event Manager: 8%
Workforce by country
- India: 0
- Canada: 0
- Australia: 0
- United States: 0
- United Kingdom: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.