CM.com N.V.

Netherlands · www.cm.com/mailplus · 14 vendors

Resilience scores

Technology vendors

Services catalogue

4 services in catalogue across 3 categories; runs on 14 sub-vendors.

Insights

Last updated 2026-07-12 · revision 2

14 direct vendors, 189 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

CM.com exhibits medium-to-high migration readiness, scoring 65. The company's "RESTful API architecture" and its suite of API-driven products (e.g., Business Messaging API, SMS Gateway API, Voice API, Email API) suggest a modular, microservices-oriented application layer that is inherently more portable. The adoption of modern technologies like Agentic AI, Conversational AI, and a Customer Data Platform (CDP) further indicates a forward-thinking tech stack. CM.com's extensive regulatory compliance (ISO 27001, ISO 42001, PCI-DSS, GDPR, HDS) is a significant advantage, as the company is well-versed in navigating complex data residency and security requirements, which would be crucial for any migration effort. The primary challenge to migration readiness stems from its "privately owned cloud platform (in-house developed, EU-hosted)" and "proprietary infrastructure." While this offers control, migrating *from* such a custom environment to a standard public cloud would likely entail a substantial re-platforming effort, representing a form of self-imposed lock-in. The "Total Vendors: 0" data point, if interpreted as minimal external core infrastructure vendors, reduces external vendor lock-in complexity, but the internal proprietary platform remains a significant hurdle. Data residency requirements, while currently met, would need careful consideration in a new environment. The absence of data on financial stability also limits the assessment of the company's capacity to fund a large-scale migration.

Compliance

10 in-scope frameworks identified; showing 3.

PSD2 — Compliant

CM.com is explicitly described as a 'Licensed PSP' (Payment Service Provider) on its homepage. PSD2 (EU Directive 2015/2366) is mandatory for all payment service providers operating in the EU. As a licensed PSP, CM.com is supervised by De Nederlandsche Bank (DNB) and must comply with PSD2 requirements including Strong Customer Authentication (SCA), open banking APIs, security requirements, and incident reporting. Risk is Low because PSP licensing requires ongoing regulatory supervision and compliance, and CM.com's licensed status confirms active compliance. The company's payments platform (online payments, POS, recurring payments, transaction processing) is built on this regulatory foundation.

Evidence: https://www.cm.com/, https://www.cm.com/payments/, https://www.cm.com/about-cm/, https://www.dnb.nl/en/supervision/registers/

ISAE 3000 (source) — Assessment Required

ISAE 3000 (International Standard on Assurance Engagements) is relevant for companies providing assurance reports on non-financial information, or for service organisations providing assurance to clients about their controls (often in the context of ISAE 3402 for service organisations, which is the international equivalent of SOC1). CM.com is a service organisation providing cloud and CPaaS services to businesses. ISAE 3402 reports may be requested by clients' auditors to obtain assurance over CM.com's controls relevant to financial reporting. Risk is Low because CM.com's ISO 27001 certification and PCI-DSS certification provide substantial assurance frameworks, and ISAE 3000/3402 is not universally required for CPaaS providers. However, for clients in regulated industries (banking, financial services), ISAE 3402 reports may be contractually required.

Evidence: https://www.cm.com/about-cm/, https://www.cm.com/industries/financial-services/

SOC 2 (source) — Assessment Required

CM.com is a cloud software and CPaaS provider serving 10,000+ businesses globally, including US-based clients (confirmed by US regional website). SOC2 (System and Organization Controls 2) is an AICPA framework commonly required by US enterprise clients when procuring cloud services. As CM.com serves US markets and enterprise clients, SOC2 Type II reports are frequently demanded in enterprise sales cycles. The absence of publicly confirmed SOC2 certification creates a medium risk: US enterprise clients may require SOC2 reports as a procurement condition, and without it, CM.com may face competitive disadvantage or contract barriers. Risk is Medium rather than High because CM.com's ISO 27001 certification provides an alternative security assurance framework widely accepted in European markets, and the company may have SOC2 reports available under NDA for enterprise clients.

Evidence: https://www.cm.com/, https://www.cm.com/about-cm/, https://www.cm.com/en-us/

Financials

Three-year financials

Financial Resilience Score: 6/10

CM.com has meaningfully improved its financial resilience over 2024-2025 through disciplined cost management, deleveraging, and a strategic pivot toward higher-margin SaaS and AI products. Net debt was reduced 25% from €81.9m to €61.9m, adjusted leverage improved from 4.5x to 3.1x, and the company refinanced its €100m convertible bonds with an €80m revolving credit facility from HSBC, ING, and ABN AMRO. Two capital raises in 2025 (€20m in February and €5m in November) strengthened the balance sheet, and a €8.8m gain on convertible bond extinguishment further improved equity. However, the company remains loss-making at the net level (–€3.8m in 2025, –€19.8m in 2024), and revenue has declined for two consecutive years (–5% in both 2024 and 2025) due to FX and lower CPaaS activity from certain large clients, suggesting some customer concentration risk. Adjusted EBITDA margin of 7.6% remains modest for a scaled SaaS/CPaaS peer group, and free cash flow was slightly negative in 2025. The 2028 target of 12-15% EBITDA margin depends on successful execution of the AI pivot (HALO) and ARR growth. Gross margin expansion (31.3%, up from 30.3%) and record EBITDA of €18.4m (+12%) demonstrate the profitability transition is working, and ARR growth of 7% to €35.9m provides a recurring revenue foundation. Management guidance of at least +30% Adjusted EBITDA growth in 2026 and resumed revenue growth from Q1 2026 provides visibility, but execution risk remains material given competitive pressure from Twilio, Sinch, Infobip, and MessageBird/Bird.

Key strengths: Net debt reduced 25% YoY (€81.9m to €61.9m), Adjusted leverage improved from 4.5x to 3.1x, Record gross margin of 31.3% (+1pp), Record EBITDA of €18.4m (+12% YoY), ARR growth of 7% to €35.9m, €25m in capital raised in 2025, Convertible bonds refinanced with €80m RCF, Cost discipline: OPEX –6%, FTE –8%, Ranked #1 CPaaS Leader by Juniper Research 4 years running, ISO 27001 and ISO 42001 (Responsible AI) certified

Risk factors: Revenue declining for two consecutive years (–5% in 2024 and 2025), Still net loss-making (–€3.8m in 2025), Customer concentration in CPaaS wholesale business, Modest 7.6% adjusted EBITDA margin, Free cash flow slightly negative in 2025, Execution risk on AI/HALO pivot, CFO transition in November 2025, Competition from Twilio, Sinch, Infobip, MessageBird/Bird, Telco price pressure and hyperscaler encroachment in CPaaS, EBIT likely negative once D&A deducted from EBITDA

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report