EQS Group

Germany · www.eqs.com · 18 vendors

Resilience scores

Technology vendors

Services catalogue

5 services in catalogue across 2 categories; runs on 18 sub-vendors.

Insights

Last updated 2026-08-07 · revision 6

18 direct vendors, 234 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

EQS Group exhibits high migration readiness, primarily driven by its modern, cloud-native technology stack and strong internal capabilities. The use of Kubernetes, CI/CD Pipelines, and a Cloud-Native Application Protection Platform (CNAPP) indicates a highly portable, containerized, and microservices-oriented architecture, which is ideal for seamless migration between cloud environments. The company's consistent revenue growth provides the financial capacity to fund complex migration projects. EQS Group possesses a mature and extensive compliance framework, with certifications and adherence to GDPR, NIS2, ISO 27001, SOC 2, DORA, and the EU AI Act. While these regulations introduce complexity, EQS's deep expertise and established processes mean they are well-equipped to manage compliance requirements during a migration. The announced migration to a new T-Systems hosting platform by April 2025 further demonstrates their experience in managing significant infrastructure transitions and vendor relationships. The primary challenge for migration is the strict 'European Economic Area only' data residency commitment. This limits migration options to EU-based cloud providers or specific regions of global providers, but it is a known and actively managed constraint. While there is a significant dependency on T-Systems for private cloud hosting, the underlying Kubernetes architecture mitigates application-level vendor lock-in, making the core platform more infrastructure-agnostic. The 'Vendor Lock-in Risk: Unknown' prevents a full assessment of contractual lock-in, but the architectural choices suggest a proactive approach to portability.

Compliance

12 in-scope frameworks identified; showing 3.

NIS2 (source) — Compliant

EQS Group is a cloud-based SaaS provider headquartered in Germany with 600+ employees and operations across 14 locations in the EU and globally. Under NIS2 Directive (EU 2022/2555), digital infrastructure and ICT service management providers are classified as Essential Entities, while digital providers (online marketplaces, online search engines, cloud computing services) are classified as Important Entities. EQS Group, as a cloud SaaS provider serving 14,000+ customers across 80+ countries with compliance-critical infrastructure, likely qualifies as an Important Entity (digital provider / cloud computing service) and potentially as an ICT service management provider. They clearly exceed the size thresholds (50+ employees, €10M+ turnover). Risk is Medium rather than Low because NIS2 compliance obligations are relatively new (transposition deadline October 2024), enforcement is still maturing across EU member states, and the specific classification of EQS under NIS2 categories requires formal regulatory determination. However, EQS has proactively listed NIS2 as a compliance item in their Trust Center, significantly reducing residual risk.

Evidence: https://trust.eqs.com/, https://www.eqs.com/security/, https://www.eqs.com/about-eqs/legal-notice/

SOC 2 (source) — Compliant

EQS Group has achieved both SOC 2 Type 1 and SOC 2 Type 2 certifications, as publicly listed in their Trust Center. SOC 2 Type 2 is the more rigorous certification, covering the operational effectiveness of security controls over a defined period (typically 6-12 months). As a cloud SaaS provider handling sensitive compliance and governance data for 14,000+ enterprise customers, SOC 2 is both applicable and actively maintained. Risk is Low because the certification is confirmed, publicly disclosed, and the company's entire business model depends on maintaining the highest security standards. The homepage explicitly advertises 'SOC 2 certification for the highest security standard' as a key trust benefit.

Evidence: https://trust.eqs.com/, https://www.eqs.com/security/, https://www.eqs.com/

MAR — Compliant

EQS Group provides MAR-compliant disclosure services (regulatory news, insider list management, ad-hoc disclosure) to listed companies. As a regulated disclosure service provider, EQS must itself comply with MAR requirements for its disclosure infrastructure. EQS is listed on the Frankfurt Stock Exchange (Scale segment), making it subject to MAR as a listed company. Their Insider Manager product and Disclosure platform are specifically designed for MAR compliance. Risk is Low given EQS's core business is MAR compliance infrastructure and they are themselves a listed company with strong incentive to maintain compliance.

Evidence: https://www.eqs.com/ir-services/insider-manager/, https://www.eqs.com/ir-services/disclosure/, https://www.eqs.com/about-eqs/investors/

Financials

Three-year financials

Financial Resilience Score: 7/10

EQS Group demonstrates solid financial resilience underpinned by a sticky SaaS revenue model with high renewal rates across 14,000+ enterprise customers, including all DAX40 companies for IR services. The company benefits from powerful regulatory tailwinds including the EU Whistleblower Protection Directive, CSRD sustainability reporting, EU AI Act, and GDPR enforcement, which drive mandatory (rather than discretionary) demand for its compliance tools. Its position as the undisputed market leader for digital IR in the DACH region provides pricing power and a defensible moat. However, the company entered a heavy investment cycle in 2022 that pushed EBIT/EBITDA significantly negative (-EUR 5.7M EBITDA in 2022), driven by cloud platform migration, whistleblowing scale-up, and international expansion. While FY2023 showed a path back toward positive EBITDA, the company remained loss-making at the EBIT level. The 2024 take-private transaction by Thoma Bravo provides deep-pocketed backing for continued investment, M&A, and consolidation (including onboarding former Convercent/OneTrust customers), materially strengthening financial resilience despite reduced disclosure transparency going forward.

Key strengths: Sticky SaaS subscription revenue with high renewal rates, 14,000+ customers including all DAX40 for IR services, Regulatory tailwinds (EU Whistleblower Directive, CSRD, AI Act, GDPR), Market leadership in DACH digital IR, Thoma Bravo ownership provides financial firepower, Diversified across four product cockpits (Compliance, Privacy, Sustainability, IR), Revenue roughly doubled 2019-2023 (~19% CAGR)

Risk factors: Loss-making EBIT profile through 2022-2023 investment cycle, Integration risk from multiple acquisitions (Business Keeper, Convercent migration), Reduced transparency post-delisting in 2024, Competitive pressure from larger US players (OneTrust, NAVEX, Diligent, Workiva), Geographic concentration ~70-75% in DACH region, Return to sustainable profitability depends on S&M efficiency scaling

Revenue by geography

Revenue by product/service

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report