e-Spirit
Germany · www.e-spirit.com · 17 vendors
Resilience scores
- Digital Sovereignty: 65
- Digital Resilience: 8
- Financial Resilience: 5
Technology vendors
- Cookiebot (Cybot A/S) — Technology — Denmark
- Demandware — Technology — United States
- Spryker — Germany
- and 14 more
Services catalogue
1 service in catalogue across 1 category; runs on 17 sub-vendors.
- FirstSpirit
Insights
Last updated 2026-08-17 · revision 1
17 direct vendors, 213 subvendors
Direct vendors by controlling owner country (sample)
- United States: 11
- Germany: 3
- Denmark: 2
Subvendors by controlling owner country (sample)
- Portugal: 2
- Unknown: 2
- Poland: 2
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
e-Spirit exhibits very high migration readiness, largely attributable to its cutting-edge and cloud-agnostic technology stack. The extensive use of Amazon Web Services (AWS) and Microsoft Azure, coupled with containerization technologies like Docker and Kubernetes, and a Microservices Architecture, positions the company for highly flexible and efficient migrations. The adoption of Headless CMS, RESTful APIs, and GraphQL further enhances portability and reduces technical lock-in. The offering of 'FirstSpirit Cloud Edition (SaaS)' explicitly demonstrates existing capabilities and experience in cloud-native deployments. While the 'Total Vendors: 0' data point is ambiguous given the 'Total Services: 15' and vendor geographic data, the technical architecture itself suggests minimal technical vendor lock-in. The geographic diversity of vendor headquarters across 4 countries also suggests a potentially less concentrated vendor landscape, which can ease vendor transitions if required. The primary limitations in fully assessing migration readiness are the lack of information on specific regulatory environments, data residency requirements, and financial stability to fund potential migration efforts. Contractual vendor lock-in risk also remains unknown due to the ambiguity in vendor data.
Compliance
9 in-scope frameworks identified; showing 3.
BDSG — Assessment Required
The BDSG is the German national data protection law that supplements and implements GDPR at the national level. As a German company headquartered in Dortmund (North Rhine-Westphalia), e-Spirit is directly subject to BDSG. Risk is High because: (1) BDSG applies to all German companies processing personal data, (2) it includes specific provisions beyond GDPR such as employee data protection (§26 BDSG), data protection officer requirements, and specific rules for video surveillance and biometric data, (3) the LDI NRW (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen) is the competent supervisory authority and has an active enforcement record, (4) non-compliance can result in both GDPR-level fines and additional BDSG-specific sanctions.
Evidence: https://www.gesetze-im-internet.de/bdsg_2018/, https://www.ldi.nrw.de/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
ISO 27001 (source) — Assessment Required
ISO 27001 certification is a strong market expectation for enterprise software and SaaS providers operating in the EU and globally. e-Spirit, as a German enterprise software company serving large organizations, would face significant competitive disadvantage without ISO 27001 certification. Risk is Medium because: (1) German enterprise software companies of e-Spirit's profile commonly pursue ISO 27001 as a baseline security credential, (2) the lack of confirmed certification represents a reputational and competitive risk, (3) NIS2 compliance (if applicable) would be significantly supported by ISO 27001 certification, (4) post-Crownpeak acquisition, the certification status may have changed. Fines are not directly associated with ISO 27001 non-certification, but contractual and reputational consequences are significant.
Evidence: https://www.iso.org/isoiec-27001-information-security.html, https://www.bsi.bund.de/EN/Topics/Certification/certification_node.html, https://www.crownpeak.com/security
German IT Security Act — Assessment Required
Germany's IT Security Act (IT-SiG 2.0, 2021) and the underlying BSI Act (BSIG) impose cybersecurity requirements on operators of critical infrastructure (KRITIS) and digital service providers. Risk is Medium because: (1) e-Spirit as a SaaS/DXP provider may qualify as a digital service provider under BSIG, (2) if any of e-Spirit's customers are KRITIS operators and rely on FirstSpirit for critical operations, supply chain security obligations may apply, (3) the IT-SiG 2.0 expanded the scope of regulated entities and introduced new obligations for companies of 'significant public interest' (UBI), (4) the NIS2 transposition (NIS2UmsuCG) will supersede and expand these requirements.
Evidence: https://www.bsi.bund.de/EN/Topics/cybersecurity-requirements/IT-Security-Act/it-security-act_node.html, https://www.gesetze-im-internet.de/bsig_2009/
Financials
Three-year financials
- 2019: revenue €30M
Financial Resilience Score: 5/10
e-Spirit AG occupied a strong niche position in the enterprise DXP/CMS market with a loyal customer base in the DACH region, including major German industrials, banks, insurers, and retailers. The company demonstrated double-digit annual revenue growth in the years leading up to its 2020 acquisition, and was recognized by Gartner and Forrester as a notable player in Web Content Management. Its recurring-revenue SaaS/subscription model provided growing revenue visibility alongside on-premise licenses. However, the company was sub-scale compared to global competitors like Adobe, Sitecore, and Salesforce, with limited R&D and marketing budgets. It operated in a highly competitive category facing commoditization pressure from headless CMS entrants such as Contentful, Contentstack, and Strapi. Following its May 2020 acquisition by Crownpeak Technology (backed by Rubicon Technology Partners), the company lost standalone financial reporting, and private equity ownership typically increases leverage and integration risk. The recent redirect of e-spirit.com to Rezolve Ai suggests the brand may be being wound down or repurposed, representing a material discontinuity. Overall resilience is moderate given the strong pre-acquisition fundamentals offset by scale disadvantages and post-acquisition uncertainty.
Key strengths: Strong niche position in enterprise DXP/CMS market, Loyal enterprise client base in DACH region, Recurring-revenue SaaS/subscription model, Recognition by Gartner and Forrester, Double-digit revenue growth pre-acquisition
Risk factors: Sub-scale versus global competitors (Adobe, Sitecore, Salesforce), Limited R&D and marketing budgets, Commoditization pressure from headless CMS entrants, Private equity ownership increases leverage/integration risk, Post-acquisition brand appears to be wound down (domain redirect to Rezolve Ai), No longer an independent reporting entity
Revenue by geography
- DACH (Germany, Austria, Switzerland): 65%
- North America: 25%
- Rest of EMEA and APAC: 10%
Revenue by product/service
- FirstSpirit CMS / DXP licenses and subscriptions: 78%
- Professional services / implementation & support: 22%
Workforce by country
- Germany: 175
- United States: 50
- Other (UK, Netherlands, Switzerland, Singapore): 50
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.