DE-CIX

Germany · www.de-cix.net · 17 vendors

DE-CIX provides premium interconnection services and operates numerous carrier and data center-neutral Internet Exchanges worldwide. The company enables networks, Internet service providers, and content providers to exchange data traffic, connect to cloud services, and ensure secure and smooth Internet operation. It was founded in 1995 in Frankfurt, Germany.

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 17 sub-vendors.

Insights

Last updated 2026-07-30 · revision 2

17 direct vendors, 209 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

DE-CIX exhibits a strong foundation for migration readiness, earning a score of 83. The company's internal technology stack is highly modern, flexible, and automation-friendly, which are critical enablers for any significant migration effort. Key technologies include Software-Defined Networking (SDN), P4 programmable data planes, EVPN, Linux, and open-source BGP tooling. Crucially, DE-CIX has embraced API-driven operations through its "DE-CIX Portal & API," which is based on the IX-API standard, allowing for programmatic ordering, configuration, and cancellation of services with full automation. This level of automation significantly streamlines infrastructure changes and potential migrations. Moreover, DE-CIX's product offerings demonstrate a clear strategic alignment with cloud adoption. Services like "DirectCLOUD" (connecting to AWS, Google Cloud, Microsoft Azure, Oracle Cloud, Alibaba Cloud), "Cloud ROUTER" (multi-cloud connectivity), and "Microsoft Azure Peering Service" indicate deep expertise and existing infrastructure for integrating with major cloud providers. The "AI Internet Exchange (AI-IX)" further highlights readiness for future, demanding cloud-native and AI-driven workloads. The availability of "Consulting" services also suggests internal expertise that can guide complex network and interconnection migrations. The primary limitations to a higher migration readiness score stem from missing data. The "Regulatory Environment" and "Data Residency Requirements" are not specified, which are crucial factors that can significantly impact migration strategies and timelines. Similarly, the "Financial Stability" data (revenue concentration, growth history) is absent, making it difficult to assess the company's capacity to fund large-scale migration projects. Regarding vendor lock-in, the data is ambiguous. While "Vendor Lock-in Risk: Unknown" is stated, and "Total Vendors: 0" is contradictory, the "Vendor Geographic Diversity: 5 unique countries" for 13 services suggests a degree of diversification that could mitigate some lock-in risks, but the actual number of vendors and contract complexities remain unknown. The core business of operating an IXP is inherently hardware-centric, meaning a full "cloud-native" transformation of its *own* core infrastructure might be less applicable than for a pure software company, but its principles of automation and cloud connectivity are highly transferable.

Compliance

10 in-scope frameworks identified; showing 3.

India DPDP Act — Assessment Required

DE-CIX operates six Internet Exchange Points in India (Bengaluru, Chennai, Delhi, Hyderabad, Kolkata, Mumbai) through its Indian subsidiary (de-cix.in), making it one of DE-CIX's largest non-European markets. India's Digital Personal Data Protection Act (DPDP Act, 2023) applies to processing of digital personal data within India and to processing outside India if it involves offering goods/services to Indian data principals. Risk is Medium because: (1) DE-CIX's Indian operations are substantial (6 IXP locations); (2) The DPDP Act introduces new obligations including consent management, data fiduciary registration, and data localization requirements for certain categories; (3) Rules under the DPDP Act are still being finalized (as of 2025), creating regulatory uncertainty; (4) Non-compliance penalties can reach INR 250 crore (~€28M) per breach.

Evidence: https://www.de-cix.in/de-cix-mumbai/?source=de-cixwebsite, https://www.de-cix.in/de-cix-delhi/?source=de-cixwebsite

SOC 2 (source) — Assessment Required

SOC 2 is a voluntary framework developed by the AICPA for service organizations that store, process, or transmit customer data in the cloud or as a service provider. DE-CIX provides cloud connectivity services (DirectCLOUD connecting to AWS, Google Cloud, Microsoft Azure, Oracle, Alibaba Cloud), a customer portal, and managed interconnection services to thousands of enterprise and carrier customers globally, including US-based customers. Many enterprise and cloud customers — particularly US-based ones — contractually require SOC 2 Type II reports from their service providers. Risk is Medium because: (1) DE-CIX's US operations and US enterprise customer base create commercial pressure for SOC 2 compliance; (2) Absence of a SOC 2 report could be a competitive disadvantage or contractual barrier; (3) However, DE-CIX's ISO 27001 BSI IT-Grundschutz certification (since 2010) provides substantial equivalent assurance and may satisfy many customer requirements. No public SOC 2 report has been found.

Evidence: https://www.de-cix.net/en/about-de-cix/corporate-it-security, https://www.de-cix.net/en/services/directcloud, https://portal.de-cix.net/

ISO 27001 (source) — Compliant

DE-CIX explicitly confirms ISO 27001 certification based on BSI IT-Grundschutz (BSI baseline protection) since 2010 on its official Corporate IT Security page, with a direct link to the BSI certification authority. This is a long-standing, continuously maintained certification (15+ years). Risk is Low because: (1) Certification is confirmed from the official company website with a link to the BSI authority; (2) The BSI IT-Grundschutz variant of ISO 27001 is a more rigorous standard than standard ISO 27001, incorporating detailed technical and organizational controls; (3) The certification has been maintained for over 15 years, indicating mature and embedded security management processes; (4) A dedicated Corporate IT Security department manages the ISMS; (5) The certification directly supports NIS2 and KRITIS compliance obligations.

Evidence: https://www.de-cix.net/en/about-de-cix/corporate-it-security, https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/IT-Grundschutz/it-grundschutz_node.html

Financials

Three-year financials

Financial Resilience Score: 8/10

DE-CIX operates a dominant, near-monopoly critical internet infrastructure business with the world's largest Internet Exchange by peak traffic in Frankfurt. Its subscription-like revenue model based on recurring peering ports and interconnection contracts provides highly predictable cash flows analogous to data-center/colocation businesses, with very high renewal rates. Structural tailwinds including ~20-25% annual traffic growth, +50% cloud connections in 2023, and emerging generative-AI data flows continue to drive port upgrades and higher-capacity products. Ownership by eco (a not-for-profit industry association) removes short-term profit pressure and enables long-term capex-heavy expansion. The company has diversified across 54 metro markets in 30+ countries, reducing dependence on any single jurisdiction. Carrier- and data-center-neutrality creates a strong competitive moat that Tier-1 telcos cannot easily replicate. However, financial transparency is limited since DE-CIX Group AG is privately held with no published consolidated IFRS financials beyond FY2017 (EUR 31.8M revenue, +9% YoY). Concentration in Frankfurt, capital intensity of new market build-outs, competitive pressure from hyperscaler direct interconnects, and FX exposure across USD/INR/BRL create meaningful risks. Overall the business model, market position, and structural growth support a strong resilience rating despite the disclosure gaps.

Key strengths: World's largest Internet Exchange by peak traffic (22.36 Tbit/s in 2023), Recurring subscription-like revenue model with high renewal rates, Structural traffic growth of 20-25% annually, 54 markets across 30+ countries providing geographic diversification, Carrier- and data-center-neutrality moat, Not-for-profit-aligned ownership by eco association enables long-term investment, Cloud connections grew +50% in 2023, 3,600+ connected networks (+16.4% YoY in 2023)

Risk factors: High capital intensity for new market build-outs in India, Americas, SE Asia, Africa, Concentration risk in Frankfurt IX, Competition from hyperscaler direct cloud on-ramps disintermediating peering, Regulatory and data-sovereignty pressure (BND surveillance history, EU digital sovereignty), Limited financial transparency as privately held entity, FX exposure across USD, INR, BRL vs EUR reporting currency, Early-stage market margins may be thin

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report