Duo Security LLC

United States · duo.com · 18 vendors

Duo Security provides cloud-based multi-factor authentication (MFA) and comprehensive identity and access management (IAM) security solutions. It helps organizations verify user identities and device health before granting access to applications, data, and networks, aligning with Zero Trust security principles.

Resilience scores

Technology vendors

Services catalogue

7 services in catalogue across 3 categories; runs on 18 sub-vendors.

Insights

Last updated 2026-07-28 · revision 2

18 direct vendors, 244 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Duo Security LLC exhibits a very high level of migration readiness, primarily driven by its advanced and modern internal tech stack. The use of cloud platforms (Amazon Web Services, Cisco Cloud Infrastructure), containerization technologies (Kubernetes, Docker), and infrastructure as code tools (Terraform, Ansible) indicates a highly agile and portable architecture. This cloud-native approach significantly reduces the complexity and effort typically associated with migrations, allowing for easier movement between environments or adoption of new technologies. The company's focus on modern development languages (Python, Go, Ruby on Rails) further supports this flexibility. Key limitations in fully assessing migration readiness stem from missing data on the regulatory environment, specific data residency requirements, and financial stability (revenue concentration, growth history). These factors could introduce unforeseen complexities or constraints during a migration. The vendor relationship data is also somewhat unclear; while "Total Vendors: 0" is stated, other details suggest some vendor dependencies with moderate geographic diversity (United States, United Kingdom, Sweden). The "Vendor Lock-in Risk: Unknown" means we cannot definitively assess the impact of vendor relationships on migration flexibility. However, the inherent portability and modularity of their modern tech stack suggest that potential vendor lock-in is likely manageable.

Compliance

12 in-scope frameworks identified; showing 3.

PIPEDA — Compliant

Duo Security explicitly references PIPEDA compliance on its compliance page. As a cloud service provider with Canadian customers (Duo serves 100,000+ customers globally including Canada), PIPEDA applies to Duo's collection, use, and disclosure of personal information in the course of commercial activities. Risk is Low because: (1) Duo explicitly references PIPEDA alignment; (2) Cisco's global privacy program covers Canadian privacy law requirements; (3) PIPEDA is being replaced by Bill C-27 (CPPA) but current compliance is maintained.

Evidence: https://duo.com/solutions/compliance

HIPAA (source) — Compliant

Duo Security explicitly markets HIPAA compliance solutions and serves healthcare customers. As a cloud service provider that processes authentication data for healthcare organizations (hospitals, clinics, telehealth providers), Duo qualifies as a Business Associate under HIPAA when its services are used to access systems containing Protected Health Information (PHI). HIPAA Business Associate obligations include executing BAAs with covered entities, implementing appropriate administrative, physical, and technical safeguards, and reporting breaches. Risk is Medium because: (1) Duo is a widely-used authentication layer in healthcare IT environments; (2) any misconfiguration or breach affecting PHI access could trigger HIPAA enforcement; (3) HHS OCR has increased enforcement actions against cloud service providers; (4) however, Duo's core function is authentication (not PHI storage), which limits direct PHI exposure. Risk is not High because Duo's role is as an authentication intermediary rather than a PHI repository.

Evidence: https://duo.com/solutions/compliance, https://duo.com/solutions/healthcare, https://trustportal.cisco.com/c/r/ctp/trust-portal.html?search_keyword=duo

PCI DSS (source) — Compliant

Duo Security explicitly references PCI-DSS compliance support on its compliance page, specifically PCI-DSS 4.0 Section 8.3 (multi-factor authentication requirements). As a cloud service provider used by retail, financial, and e-commerce customers to secure cardholder data environments (CDE), Duo must comply with PCI-DSS requirements applicable to service providers. Risk is Low because: (1) Duo explicitly supports PCI-DSS 4.0 MFA requirements; (2) Duo's MFA functionality directly satisfies PCI-DSS Section 8.3 requirements; (3) as a service provider to PCI-DSS merchants, Duo maintains its own PCI-DSS compliance program; (4) Duo serves retail customers (explicitly listed as an industry vertical).

Evidence: https://duo.com/solutions/compliance, https://duo.com/solutions/retail, https://duo.com/solutions/financial

Financials

Three-year financials

Financial Resilience Score: 9/10

Duo Security's financial resilience is effectively tied to its parent company, Cisco Systems, Inc., which acquired Duo in October 2018 for approximately US$2.35 billion in cash. As a wholly-owned subsidiary and product line within Cisco's Security business unit, Duo no longer files standalone financial statements, and its results are consolidated into Cisco's SEC filings without a separate Duo-only line item. This means external stakeholders cannot independently assess Duo's unit-level profitability, growth, or capital position. However, the resilience of the parent is exceptionally strong. Cisco reported FY2024 revenue of approximately US$53.8B, net income of ~US$10.3B, and stockholders' equity of ~US$44.6B, with an investment-grade credit rating (A+/AA-). Duo operates within Cisco's Security segment, which grew to ~US$5.7B in FY2024 (boosted by the Splunk acquisition), from ~US$4.0B in FY2023 and ~US$3.6B in FY2022. Duo's subscription-based SaaS model provides predictable, recurring revenue with strong retention and >1.3 billion monthly authentications. Risks include competitive pressure from Okta, Microsoft Entra ID, Ping Identity, and others; Microsoft's bundling of MFA/SSO into E3/E5 licenses that may compress Duo's addressable market; and integration/positioning risk within Cisco's broader security portfolio, particularly post-Splunk rationalization.

Key strengths: Wholly-owned by Cisco Systems (NASDAQ: CSCO) with investment-grade credit rating (A+/AA-), Cisco FY2024 revenue ~US$53.8B, net income ~US$10.3B, stockholders' equity ~US$44.6B, Recurring SaaS subscription revenue model with strong retention, Leadership position in identity/MFA with >1.3 billion monthly authentications, Cross-sell opportunity into Cisco's massive enterprise customer base, Strong end-market tailwinds in zero-trust, phishing-resistant MFA, and ITDR

Risk factors: No standalone financial transparency post-acquisition, Competitive pressure from Okta, Microsoft Entra ID, Ping Identity, CyberArk, JumpCloud, and Google, Microsoft bundling MFA/SSO into E3/E5 licenses compresses addressable market, Integration and positioning risk within Cisco, particularly post-Splunk portfolio rationalization, Product overlap with other Cisco security offerings (e.g., Identity Services Engine)

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report