EPLAN GmbH & Co. KG

Germany · www.eplan-software.com · 12 vendors

EPLAN GmbH & Co. KG provides software and service solutions in the fields of electrical, automation, and mechatronic engineering. The company develops leading design software for machine and panel builders. Its solutions aim to streamline challenging engineering processes for customers worldwide.

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 12 sub-vendors.

Insights

Last updated 2026-07-29 · revision 7

12 direct vendors, 200 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

EPLAN exhibits high migration readiness, largely due to its existing significant adoption of cloud services and a strategic move towards modern architectures. The company benefits from strong financial backing from the Friedhelm Loh Group, providing ample resources for potential migration initiatives. Their internal tech stack already utilizes Microsoft Azure for cloud hosting of the Eplan Cloud, and they leverage various SaaS platforms like Salesforce, HubSpot, and Adobe, indicating experience with cloud environments. The development of Eplan Cloud, Collaboration Apps, and AI-powered tools like Eplan Copilot further demonstrates a commitment to cloud-native and modern solutions. A robust compliance framework (GDPR, SOC2, ISO 27001) provides a solid foundation for secure migration. However, challenges exist: the 'Eplan Platform' and 'Eplan Electric P8' are described as foundational and flagship software, which might imply legacy components requiring significant refactoring for a full cloud-native migration. Data residency requirements, while managed through Standard Contractual Clauses with primarily US-based vendors, add complexity, especially with potential customer-specific localization demands. The 'Assessment Required' status for NIS2 could introduce new compliance hurdles during a migration. The explicit 'Total Vendors: 0' in the vendor relationships section is a data gap regarding their explicit vendor management strategy, which could impact the complexity of managing vendor contracts and dependencies during a large-scale migration.

Compliance

12 in-scope frameworks identified; showing 3.

MLPS 2.0 — Compliant

EPLAN explicitly lists MLPS 2.0 compliance on its Trust Center page, confirming active engagement with China's cybersecurity and data protection regulatory framework. Risk is Medium because: (1) MLPS 2.0 compliance is confirmed, reducing regulatory risk in China; (2) however, China's data regulatory environment is complex and evolving, including the Cybersecurity Law (CSL), Data Security Law (DSL), and Personal Information Protection Law (PIPL), which impose additional obligations beyond MLPS 2.0; (3) EPLAN has a dedicated China presence (eplan.com/zh/ and eplan.com/en/ for China), indicating significant Chinese operations; (4) cross-border data transfer restrictions under PIPL and DSL require security assessments or standard contracts for data leaving China; (5) enforcement risk in China is elevated for foreign technology companies.

Evidence: https://www.eplan.com/de-en/services/trust-and-security/multi-level-protection-scheme-20/, https://www.eplan.com/de-en/services/trust-and-security/, https://www.eplan.com/zh/, https://www.eplan.com/en/

Cyber Resilience Act (source) — Assessment Required

The EU Cyber Resilience Act (CRA, Regulation 2024/2847) entered into force in December 2024, with most obligations applying from December 2027. EPLAN is a software product manufacturer (Eplan Electric P8, Eplan Pro Panel, Eplan Data Portal, Eplan Platform, Eplan Cloud) — precisely the type of entity the CRA targets. Risk is High because: (1) EPLAN's software products (both on-premise and cloud/SaaS) are 'products with digital elements' under the CRA; (2) the CRA imposes mandatory cybersecurity requirements for the entire product lifecycle, including design, development, vulnerability handling, and security updates; (3) EPLAN may be classified as a 'Class I' or 'Class II' important product depending on product category, triggering stricter conformity assessment requirements; (4) non-compliance can result in market withdrawal and fines up to €15M or 2.5% of global annual turnover; (5) the CRA is a new regulation with significant implementation complexity for software vendors; (6) EPLAN's cloud services (Eplan Cloud) may also fall under the CRA's scope for remote data processing solutions.

Evidence: https://www.eplan.com/de-en/services/trust-and-security/, https://www.eplan.com/de-en/products/eplan-platform/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R2847

German IT Security Act — Assessment Required

As a German-headquartered technology company providing software to critical infrastructure operators, EPLAN may be subject to the German IT Security Act (IT-SiG 2.0, 2021) and the BSI Act (BSIG). The IT-SiG 2.0 expanded KRITIS (critical infrastructure) obligations and introduced new requirements for companies 'of special public interest' (UBI — Unternehmen im besonderen öffentlichen Interesse). EPLAN's software is used by energy companies, automotive manufacturers, and infrastructure operators, but EPLAN itself is a software vendor, not a KRITIS operator. Risk is Medium because: (1) NIS2 transposition (NIS2UmsuCG) supersedes and expands IT-SiG 2.0 obligations; (2) EPLAN's classification as UBI or KRITIS operator requires formal BSI assessment; (3) EPLAN's proactive NIS2 and ISO 27001 posture suggests awareness of these obligations.

Evidence: https://www.eplan.com/de-en/services/trust-and-security/eu-nis-2-directive/, https://www.eplan.com/de-en/services/trust-and-security/iso-iec-27001/

Financials

Three-year financials

Financial Resilience Score: 7/10

EPLAN GmbH & Co. KG benefits from being embedded within the privately held, family-owned Friedhelm Loh Group, which reported approximately €3.1 billion in revenue in FY2024 and employs around 12,600 people worldwide. The group's debt-averse family ownership provides balance-sheet resilience and long investment horizons, insulating EPLAN from short-term market pressures. EPLAN itself operates a sticky, recurring-revenue engineering CAE software model with heavy switching costs, serving a blue-chip customer base including 19 of the 20 largest automotive OEMs and 70 of the top 100 machine/plant builders globally. However, EPLAN is exposed to cyclical end-markets (automotive, machinery, industrial automation), particularly in Germany and the broader DACH region, which is currently under industrial pressure. The company faces competitive pressure from Siemens, AutoCAD Electrical, Zuken E3, and emerging cloud-native CAE vendors. As a private KG within a private group, financial transparency is limited, with no public disclosure of EPLAN-specific revenue, EBIT, or equity, making external assessment of profitability and leverage difficult. The ongoing transition to cloud/SaaS licensing (Eplan Cloud, Eplan Copilot) should improve revenue predictability over time.

Key strengths: Backing of debt-averse family-owned Friedhelm Loh Group (~€3.1B revenue, 12,600 employees), Sticky recurring revenue software model with high switching costs, Blue-chip customer base: 19 of 20 largest automotive OEMs, 70 of top 100 machine/plant builders, Ecosystem lock-in via SAP, Siemens Teamcenter integrations and 2.3M+ components in Data Portal, Strategic partnership with sister company Rittal in panel building/automation, Transition to cloud/SaaS licensing improving revenue predictability

Risk factors: Cyclical exposure to automotive, machinery, and industrial automation end-markets, Geographic concentration in DACH/Europe amid European industrial malaise, Competitive pressure from Siemens (EDA/COMOS), AutoCAD Electrical, Zuken E3, and cloud-native entrants, Limited financial transparency as a private KG within a private group, Talent and wage inflation in German software engineering hubs

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report