Cloudflare, Inc.
United States · owned by Independent (United States) · cloudflare.com · 62 vendors
Cloudflare, Inc. is a global cloud services provider that offers a broad range of services to businesses of all sizes and in all geographies. The company’s network serves as a scalable, unified control plane to deliver security, performance, and reliability for on-premises, hybrid, cloud, and SaaS applications.
Resilience scores
- Digital Sovereignty: 81
- Digital Resilience: 9
- Financial Resilience: 7
Disruption prediction
Cloudflare, Inc. has a 100% probability of disruption in the next 6 months.
All systems operational (last checked 2026-09-18 16:25 UTC)
33 of Cloudflare, Inc.'s 62 vendors monitored for disruptions.
Technology vendors
- Adobe Inc. — Technology — United States
- Broadcom Inc. — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 60 more
Services catalogue
58 services in catalogue across 11 categories; runs on 62 sub-vendors.
- Core Product
- Edge and Access Control
- HTTP/3
Insights
Last updated 2026-09-13 · revision 45
62 direct vendors, 386 subvendors
Direct vendors by controlling owner country (sample)
- Brazil: 1
- Romania: 1
- Australia: 2
Subvendors by controlling owner country (sample)
- Moldova: 1
- Australia: 5
- Sweden: 10
Migration Readiness: 10/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Cloudflare exhibits exceptionally high migration readiness, scoring 95 out of 100. This is largely due to its inherently cloud-native and modern architectural approach. The internal tech stack utilizes containerization (Docker, Kubernetes), serverless computing (Cloudflare Workers), and microservices principles, making its systems highly portable and adaptable for migration to or within modern cloud environments. A critical factor contributing to high readiness is the explicit statement of 'Total Vendors: 0' in the provided data. If accurate for critical services, this indicates virtually no external vendor lock-in, meaning Cloudflare is not constrained by external vendor contracts, proprietary technologies, or roadmaps that could complicate or delay a migration. (It is important to note the inconsistency with the subsequent listing of 'Vendor HQ Countries' and 'Vendor Geographic Diversity,' which suggests some vendor relationships exist; for this assessment, we prioritize the explicit 'Total Vendors: 0' for critical services). Cloudflare also possesses robust data residency capabilities through its extensive global network and Data Localization Suite, offering granular controls for data processing and storage, which is crucial for migrations involving sensitive or regulated data. Financially, the company's strong and growing revenue provides ample resources to fund and execute complex migration projects. The primary challenges for migration readiness stem from potential internal platform lock-in; while external vendor lock-in is minimal, migrating away from Cloudflare's vast and integrated ecosystem of its own highly optimized products could still present significant engineering challenges. Additionally, the 'Unknown' status for SOC2 and ISO 27001 certifications and 'Assessment Required' for NIS2 could introduce complexity if a migration necessitates achieving or proving compliance with these standards, adding to project scope and timeline.
Compliance
12 in-scope frameworks identified; showing 3.
ISAE 3000 (source) — Compliant
ISAE 3000 is applicable to Cloudflare as the international standard underpinning assurance reports such as SOC 2 (which is based on ISAE 3000 for non-financial information assurance). Cloudflare's SOC 2 Type II reports are conducted in accordance with ISAE 3000 standards by independent auditors. Risk is Low because Cloudflare's existing SOC 2 Type II program inherently satisfies ISAE 3000 requirements. The standard is applied through the third-party audit process rather than requiring separate certification.
Evidence: https://www.cloudflare.com/trust-hub/compliance-resources/, https://dash.cloudflare.com/?to=/:account/compliance-docs, https://developers.cloudflare.com/fundamentals/reference/policies-compliances/compliance-docs/
SOC 2 (source) — Compliant
Cloudflare is a major cloud services and internet infrastructure provider — SOC 2 is directly applicable and critically important for its enterprise customer base. Risk is Low because Cloudflare has publicly confirmed SOC 2 Type II certification, which is the most rigorous form of SOC 2 attestation (covering a period of time rather than a point-in-time assessment). SOC 2 Type II demonstrates sustained operational effectiveness of security controls. This certification is a key trust signal for Cloudflare's enterprise customers and is actively maintained. The risk of non-compliance is minimal given the company's demonstrated commitment and the availability of reports through its compliance dashboard.
Evidence: https://www.cloudflare.com/trust-hub/compliance-resources/, https://dash.cloudflare.com/?to=/:account/compliance-docs, https://developers.cloudflare.com/fundamentals/reference/policies-compliances/compliance-docs/, https://www.cloudflare.com/trust-hub/
ISO 27701 — Compliant
ISO 27701 extends ISO 27001 to cover privacy information management, directly relevant to Cloudflare's role as both a data controller and data processor. Risk is Low because Cloudflare has obtained ISO 27701 certification, demonstrating a systematic approach to privacy management that complements its GDPR and CCPA compliance programs.
Evidence: https://www.cloudflare.com/trust-hub/compliance-resources/, https://dash.cloudflare.com/?to=/:account/compliance-docs, https://developers.cloudflare.com/fundamentals/reference/policies-compliances/compliance-docs/
Financials
Three-year financials
- 2025: revenue USD 2.17B, EBIT USD -207M, equity USD 1.46B
- 2024: revenue USD 1.67B, EBIT USD -155M, equity USD 1.05B
- 2023: revenue USD 1.30B, EBIT USD -185M, equity USD 763M
Financial Resilience Score: 7/10
Cloudflare demonstrates strong financial resilience driven by durable high-growth revenue (~30% YoY at $1.5B+ scale), high GAAP gross margins of approximately 75-78%, and a healthy balance sheet with roughly $1.8B in cash and marketable securities at end-FY2024. The company has been free cash flow positive since 2022 (~$167M FCF in FY2024) and non-GAAP operating profitable since FY2022, indicating underlying business model viability. However, the company continues to post GAAP operating and net losses, primarily due to stock-based compensation expenses of $300-400M annually, which creates structural shareholder dilution. The diversified customer base (42% of Fortune 500 as paying customers, 4,400+ large customers with >$100K ARR) and strong dollar-based net retention of 110-115% mitigate concentration risk. Convertible notes due 2026/2030 are well-covered by current cash reserves. Competitive intensity from hyperscalers (AWS, Azure, GCP), CDN incumbents (Akamai, Fastly), and security players (Zscaler, Palo Alto) represents an ongoing risk, as does rising capital intensity from AI infrastructure buildout. Overall, Cloudflare's financial position is solid for a growth-stage infrastructure company, though GAAP profitability remains elusive.
Key strengths: Seven consecutive years of ~30%+ revenue growth, High GAAP gross margins of ~75-78%, Strong balance sheet with ~$1.8B cash and marketable securities, Free cash flow positive since 2022 (~$167M FCF in FY2024), Diversified customer base: 42% of Fortune 500 as paying customers, Strong dollar-based net retention of 110-115%, 4,400+ large customers (>$100K ARR), Non-GAAP operating profitable since FY2022
Risk factors: Persistent GAAP operating and net losses, High stock-based compensation ($300-400M annually) causing dilution, Intense competition from hyperscalers and security incumbents, Macro sensitivity for SMB/Pay-as-you-go segments, Rising capital intensity from AI inference infrastructure buildout, Geopolitical/regulatory exposure as global network operator, Dual-class share structure limits shareholder influence
Revenue by geography
- United States: 50%
- EMEA: 28%
- APAC: 14%
- Other: 8%
Workforce by country
- United States: 2058
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.