CIQ
United States · ciq.com · 12 vendors
Resilience scores
- Digital Sovereignty: 92
- Digital Resilience: 7
- Financial Resilience: 5
Technology vendors
- HubSpot, Inc. — Technology — United States
- Looker — Technology — United States
- Netlify, Inc. — Technology — United States
- and 9 more
Services catalogue
2 services in catalogue across 2 categories; runs on 12 sub-vendors.
- Enterprise Support
- Personal Data Processing
Insights
Last updated 2026-08-02 · revision 2
12 direct vendors, 219 subvendors
Direct vendors by controlling owner country (sample)
- United States: 11
- Denmark: 1
Subvendors by controlling owner country (sample)
- United Kingdom: 4
- France: 4
- Italy: 1
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
CIQ exhibits a high level of migration readiness, primarily driven by its highly modern, cloud-native oriented internal tech stack. The extensive use of Go, Python, Kubernetes (Operator SDK), Terraform, Docker, Apptainer containers, and Ansible automation indicates a strong foundation for migrating workloads to cloud environments. Containerization and orchestration capabilities are key enablers for seamless migration and portability. The adoption of Infrastructure as Code (Terraform) and CI/CD pipelines (GitHub Actions) further streamlines the migration process. While data on regulatory environment and data residency requirements is not specified, which could introduce complexities, the technical readiness is exceptionally strong. Financial stability (revenue concentration, growth history) is also unknown, which could impact the ability to fund a large-scale migration. Regarding vendor relationships, although 'Total Vendors: 0' is stated, 'Total Services: 6' from vendors in '2 unique countries' suggests a manageable vendor landscape. The modern tech stack inherently reduces technical vendor lock-in, providing flexibility for migration. The 'Vendor Lock-in Risk' is unknown, but the technological choices suggest a high degree of independence and adaptability.
Compliance
7 in-scope frameworks identified; showing 3.
GDPR (source) — Assessment Required
CIQ is a US-headquartered company (Reno, Nevada) but explicitly operates in the UAE (Abu Dhabi office) and serves global enterprise customers including those in the EU/EEA. Its website uses cookies (Cookie Policy published), collects personal data from website visitors and customers globally, and its Rocky Linux platform is used by enterprises worldwide including in Europe. As a B2B software and infrastructure company serving 90% of Fortune 100 companies globally, it is highly likely that CIQ processes personal data of EU/EEA residents (employees, customers, partners, website visitors). The risk is Medium rather than High because CIQ is primarily a software/infrastructure vendor (not a data broker or consumer-facing platform), and the volume of EU personal data processed may be limited relative to its US-centric operations. However, failure to maintain GDPR compliance mechanisms (DPA agreements, SCCs, privacy notices) could result in fines up to €20M or 4% of global annual turnover.
Evidence: https://ciq.com/legal/privacy-policy, https://ciq.com/legal/cookie-policy, https://trust.ciq.com/, https://ciq.com/company/about
ISO 27001 (source) — Assessment Required
CIQ serves 90% of Fortune 100 companies, government agencies, and research institutions — customer segments that frequently require ISO 27001 certification from their infrastructure vendors. CIQ explicitly markets itself as serving 'regulated environments' and offers compliance-focused products (RLC Pro Hardened, FIPS 140-3 validated cryptography, DISA STIG-hardened builds, CMMC-ready configurations). This compliance-forward positioning suggests awareness of and likely pursuit of ISO 27001. However, no ISO 27001 certificate was publicly confirmed. Risk is Medium because the absence of ISO 27001 could be a barrier to enterprise and government sales, and CIQ's security posture claims (FIPS, STIG, CMMC) would be strengthened by ISO 27001 certification.
Evidence: https://trust.ciq.com/, https://ciq.com/products/rocky-linux/pro/hardened, https://ciq.com/press/ciq-announces-fips-compliance-for-rocky-linux-empowering-secure-open-source-adoption, https://ciq.com/company/about
SOC 2 (source) — Assessment Required
CIQ is a cloud services and enterprise software provider. Its products include Fuzzball (multi-cloud AI/HPC orchestration), Ascender Pro (IT automation), and portal/support services (portal.ciq.com). These cloud-delivered or SaaS-adjacent services make SOC2 highly relevant. CIQ has a Trust Center (trust.ciq.com) powered by Vanta — a compliance automation platform commonly used to pursue and maintain SOC2 certification. The existence of a Vanta-powered Trust Center is a strong indicator that CIQ is either pursuing or has obtained SOC2 certification. However, no SOC2 Type I or Type II report was publicly confirmed. Risk is Medium because enterprise customers (especially Fortune 100 companies and government agencies) typically require SOC2 reports from infrastructure vendors, creating commercial pressure to maintain compliance. Failure to obtain SOC2 could result in lost enterprise deals.
Evidence: https://trust.ciq.com/, https://ciq.com/company/about, https://portal.ciq.com/login
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 5/10
CIQ is a private, venture-backed US enterprise-software company with limited financial disclosure. The company has raised at least $26M in disclosed institutional capital via its May 2022 Series A led by Two Bear Capital, plus undisclosed seed/bridge amounts from IAG Capital Partners and OpenDrives. No revenue, EBIT, or equity figures are publicly available, making a full financial resilience assessment difficult. Strategic positioning is strong, anchored by Rocky Linux (2.75M+ active instances, used by 90% of Fortune 100 companies via CIQ-supported technologies), and the company benefits from AI infrastructure tailwinds, CentOS 7 and Amazon Linux 2 end-of-life migration catalysts, and federal compliance credentials (FIPS 140-3 validation). However, financial opacity is a real concern: with only one disclosed institutional round nearly 3.5 years old, runway and burn are unknown. Competitive pressure from well-capitalized incumbents (Red Hat/IBM, SUSE, Canonical, Oracle Linux) and hyperscaler-native tools in HPC/AI orchestration is intense. The company's dependence on Rocky Linux, which is governed by the community-run RESF rather than CIQ itself, creates both a differentiator and a governance risk. Overall, the qualitative moat is strong but financial visibility is limited, warranting a mid-range resilience score.
Key strengths: Strong strategic moat around Rocky Linux (2.75M+ active instances, 90% of Fortune 100 usage), AI infrastructure and sovereign AI tailwinds, CentOS 7 and Amazon Linux 2 (June 2026) end-of-life migration catalysts, FIPS 140-3 validation (April 2025) opens federal/defense budgets, Ecosystem partnerships with Google Cloud, NVIDIA, and AMD, Nine enterprise products spanning OS, orchestration, provisioning, automation, and containers, $26M Series A led by Two Bear Capital (May 2022), Founder Gregory Kurtzer's credibility (creator of CentOS, Warewulf, Singularity/Apptainer)
Risk factors: No published financial statements — full opacity on revenue, EBIT, equity, and runway, Only one disclosed institutional round ($26M Series A in 2022) — potential runway concerns 3.5 years post-raise, Competitive pressure from Red Hat (IBM), SUSE, Canonical, Oracle Linux, Competition in HPC/AI orchestration from Slurm ecosystem, Run:ai (NVIDIA), Anyscale, hyperscalers, Rocky Linux governance dependency — CIQ does not own the distribution it commercializes, Unknown customer concentration risk, Founder/key-person concentration around Gregory Kurtzer
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.