Cogent Communications

United States · www.cogentco.com · 22 vendors

Cogent Communications is a multinational internet service provider offering high-quality Internet access, Ethernet, and Colocation services. The company operates a facilities-based, all-optical IP data-only network across North America, Europe, and Asia, serving both corporate and netcentric customer segments.

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 3 categories; runs on 22 sub-vendors.

Insights

Last updated 2026-09-13 · revision 12

22 direct vendors, 210 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Cogent Communications exhibits a medium-low level of migration readiness, scoring 42. While they have some foundational elements, significant challenges exist for a comprehensive internal system migration. **Strengths:** * **Cloud Connectivity Offerings:** Cogent's provision of 'Cloud Connect Solutions' to major public cloud platforms (AWS Direct Connect, Azure ExpressRoute, Google Cloud Interconnect) for its customers indicates familiarity with cloud environments and established network pathways to these providers. This experience could be leveraged for their own internal migrations. * **SD-WAN Capabilities:** Offering SD-WAN solutions suggests an understanding of modern network architectures that can facilitate hybrid cloud and multi-cloud strategies, which are often crucial for phased migrations. * **Financial Stability:** A strong revenue base provides the financial capacity to fund potentially large-scale migration projects. **Weaknesses & Challenges:** * **Legacy Internal Tech Stack:** The most significant challenge is the heavy reliance on on-premises, legacy Microsoft applications (Exchange, SharePoint, Dynamics GP/NAV) and Windows Server infrastructure (Active Directory, DNS, DHCP, IIS, WSUS, RDS, Failover Clustering). Joomla as a CMS also represents a legacy platform. Migrating these systems would likely involve extensive re-platforming, re-architecting, or complex lift-and-shift operations, requiring substantial time, effort, and cost. There is no evidence of widespread internal adoption of cloud-native, containerized, or microservices architectures. * **Complex Regulatory Environment:** Varying global data residency requirements, especially in the EU (GDPR) and for critical infrastructure, will significantly constrain cloud provider selection and architecture design. The 'High' risk and 'Assessment Required' status for NIS2, along with unknown SOC2 and ISO 27001 statuses, mean that any migration must be meticulously planned to ensure compliance, adding complexity and potential delays. * **Technology Lock-in:** While the 'Total Vendors: 0' data is contradictory, the internal tech stack implies significant lock-in to specific legacy technologies (e.g., on-premises Microsoft Exchange, Dynamics). Moving away from these would be a substantial undertaking, regardless of the number of underlying vendors. * **Data Residency Constraints:** As a global telecommunications provider, Cogent faces stringent data residency requirements across its 57 operating countries. This will necessitate careful consideration of cloud regions and data placement strategies, potentially limiting the benefits of global cloud scalability and increasing architectural complexity during migration.

Compliance

7 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 is directly relevant to Cogent as a global telecommunications and data center operator. The standard is widely adopted in the ISP and data center industry and is frequently required by enterprise and government customers. The risk is Medium because: (1) Lack of ISO 27001 certification may affect Cogent's ability to win contracts with security-conscious enterprise customers; (2) As a critical infrastructure provider operating in 57 countries, robust information security management is essential; (3) ISO 27001 certification would also support NIS2 compliance (Article 24 of NIS2 references use of European cybersecurity certification schemes). However, many ISPs maintain ISO 27001 certifications for specific facilities or business units rather than enterprise-wide, and Cogent may hold certifications not publicly advertised.

Evidence: https://www.cogentco.com/en/network/cogent-data-centers, https://www.cogentco.com

SOC 2 (source) — Assessment Required

SOC 2 is highly relevant to Cogent given its colocation and data center services, cloud connectivity offerings (Cloud Connect for AWS, Azure, Google Cloud), and managed network services. Customers in regulated industries (finance, healthcare, government) routinely require SOC 2 Type II reports from their infrastructure and connectivity providers as part of vendor due diligence. The risk is Medium because: (1) Absence of a publicly disclosed SOC 2 report may create competitive disadvantage and customer trust issues; (2) Enterprise and carrier customers increasingly mandate SOC 2 compliance in procurement processes; (3) Cogent's colocation and utility computing services place it squarely in the scope of SOC 2 applicability. However, many ISPs maintain SOC 2 reports that are shared under NDA rather than publicly disclosed, so absence of public evidence does not confirm non-compliance.

Evidence: https://www.cogentco.com/en/products-and-services/colocation, https://www.cogentco.com/en/solutions/cloud-connect-solutions

GDPR (source) — Partially Compliant

Cogent has taken meaningful steps toward GDPR compliance — publishing a dedicated GDPR statement (last updated April 2023), a Privacy Policy referencing GDPR obligations (last updated April 2024), maintaining a named Data Privacy Contact, and listing 20+ EU/EEA legal entities as data controllers. However, no independent third-party GDPR audit or Data Protection Officer (DPO) appointment is publicly disclosed. The company's own GDPR page acknowledges it processes 'Business Contact Personal Data' as a data controller, and its Privacy Policy confirms cross-border transfers of EEA personal data to the United States. The absence of publicly documented Standard Contractual Clauses (SCCs), Transfer Impact Assessments (TIAs), or a named DPO introduces residual medium risk. Enforcement risk is moderate: Cogent is a large multinational ISP with EU subsidiaries in 20+ countries, making it a plausible target for supervisory authority scrutiny, but its data processing activities are relatively limited (primarily business contact data rather than large-scale consumer profiling).

Evidence: https://www.cogentco.com/cogent-gdpr, https://www.cogentco.com/privacy-policy, https://www.cogentco.com/en/offices/europe

Financials

Three-year financials

Financial Resilience Score: 5/10

Cogent Communications presents a mixed financial resilience profile. On the positive side, it maintains a strong strategic position as one of only a few Tier-1 ISPs globally, with settlement-free peering with 23 major ISPs, ~19,000 miles of owned inter-city fiber, and 3,453 on-net buildings across 264 metros in 56 countries. Revenue grew 10.1% in 2024 to $1.04B, driven by strong performance in enterprise (+26.2%) and wavelength services (+240%). The company also has valuable IPv4 address holdings (~38 million addresses valued at $458M) that were successfully monetized via a $206M securitization in May 2024, and maintains a diversified customer base with top 25 customers representing only ~17.6% of revenue. However, significant concerns weigh on resilience. The company posted operating losses of -$197.6M in 2024 and -$129.3M in 2023, driven by Sprint integration costs, higher depreciation, and TSA charges. Total indebtedness stands at ~$2.0B (excluding operating and finance leases), with $500M of 2026 Notes creating near-term refinancing risk. The dramatic dividend cut in Q4 2025 from $1.015 to $0.02 per share—breaking 50+ consecutive quarters of increases—signals significant capital allocation strain. Accumulated deficit reached $376.3M at year-end 2024, and cash on hand of $227.9M is modest relative to debt obligations. Persistent enterprise/non-core customer churn from the Sprint acquisition (-28.8% and -51.5% respectively in 2024) and industry deflation (net-centric pricing down 14.2% YoY) further pressure the outlook.

Key strengths: Tier-1 ISP status with settlement-free peering with 23 major ISPs, Diversified customer base with top 25 customers only ~17.6% of revenue, Revenue growth of 10.1% in 2024 driven by enterprise and wavelength services, Owned fiber network of ~19,000 miles from Sprint acquisition, Valuable IPv4 address portfolio (~38 million addresses valued at $458M), Successful IPv4 securitization raising $206M in May 2024, Wavelength revenue growth of 240% YoY, $1.6B returned to shareholders cumulatively via dividends and buybacks

Risk factors: Substantial leverage with ~$2.0B in indebtedness plus $538.4M finance leases, $500M 2026 Notes refinancing risk maturing May 2026, Persistent operating losses (-$197.6M in 2024, -$129.3M in 2023), Q4 2025 dividend cut from $1.015 to $0.02 per share signals capital strain, Net-centric pricing declining 14.2% YoY due to industry deflation, High enterprise customer churn (-28.8%) and non-core churn (-51.5%) in 2024, Accumulated deficit of $376.3M at year-end 2024, Related-party leases with CEO-owned entities (governance flag), Interest rate swap exposure with $22.3M liability at year-end 2024, Corporate segment hampered by elevated office vacancy rates

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report