Esri

United States · www.esri.com · 42 vendors

Esri is an American geographic information system (GIS) software company headquartered in Redlands, California. It is best known for its ArcGIS products, which offer a comprehensive suite of software tools to enable users to collect, manage, analyze, and visualize geographic data. Esri's technology is used by organizations worldwide for purposes ranging from urban planning to environmental management and business analytics.

Resilience scores

Disruption prediction

Esri has an estimated 11% probability of disruption in the next 6 months.

26 of Esri's 42 vendors monitored for disruptions.

Technology vendors

Services catalogue

10 services in catalogue across 2 categories; runs on 42 sub-vendors.

Insights

Last updated 2026-07-30 · revision 10

42 direct vendors, 328 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Esri exhibits a very high level of technical migration readiness due to its modern, cloud-native, and containerized internal tech stack. The extensive use of Amazon Web Services (AWS), Microsoft Azure, Kubernetes, Docker, Apache Kafka, and other contemporary technologies indicates a strong architectural foundation for portability and re-platforming. Their existing multi-cloud strategy (AWS and Azure) further reduces vendor lock-in to a single cloud provider, offering flexibility for future migrations or hybrid deployments. The company's strong financial growth (USD 1.2B revenue in 2023) provides ample resources to fund significant migration initiatives. Products like ArcGIS Online (cloud-based) and ArcGIS Enterprise (on-premises/private cloud) demonstrate their experience operating across different deployment models. However, significant challenges for migration readiness stem from its complex regulatory environment and stringent data residency requirements. Esri faces multiple 'Assessment Required' regulations (GDPR, NIS2, HIPAA, SOC2, ISO 27001) with no public audit evidence. Addressing these compliance gaps will add considerable complexity, cost, and time to any migration effort, as new environments must be designed and validated to meet these standards. Furthermore, as a global GIS provider serving government and critical infrastructure organizations, Esri faces 'significant data residency requirements' that mandate data remain within national boundaries. This necessitates complex multi-region or sovereign cloud architectures, increasing the difficulty and expense of migrating sensitive location data. The vendor relationship data states 'Total Vendors: 0', which is contradictory given the use of AWS and Azure. Assuming these are key infrastructure vendors, their multi-cloud approach inherently mitigates single-vendor lock-in, which is a positive for migration flexibility. Despite the excellent technical foundation, the regulatory and data residency complexities will be major practical hurdles in any large-scale migration.

Compliance

6 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

NIS2 may apply as Esri provides critical digital infrastructure services (GIS software) to essential entities including government agencies, utilities, and transportation organizations across the EU. As a large enterprise with 6,000+ employees serving critical infrastructure customers, they may qualify as an Important Entity under digital service provider categories. Risk is medium due to potential significant operational restrictions and security requirements.

Evidence: https://www.esri.com/en-us/about/about-esri/company

ISO 27001 (source) — Assessment Required

ISO 27001 is critical for Esri as they handle sensitive geospatial data for government agencies, defense organizations, and critical infrastructure providers. Their global operations and customer base of 700,000+ organizations including national governments require robust information security management. Risk is high due to the sensitive nature of location data and government customer requirements.

Evidence: https://www.esri.com/en-us/about/about-esri/company

HIPAA (source) — Assessment Required

HIPAA likely applies as Esri serves healthcare organizations and has a Chief Medical Officer (Dr. Este Geraghty) leading health solutions. Their GIS technology is used for health analytics and epidemiological mapping, potentially processing PHI. Risk is medium due to potential for significant penalties and the specialized nature of healthcare compliance requirements.

Evidence: https://www.esri.com/en-us/about/about-esri/company

Financials

Three-year financials

Financial Resilience Score: 8/10

Esri operates as a privately held company with a highly stable, recurring revenue model driven by long-term enterprise and government GIS subscriptions. Its dominant market position in spatial infrastructure and deep integration into critical public and private sector workflows provide strong cash flow predictability and low customer churn. However, the lack of public financial transparency and concentration in a single software ecosystem limit external risk modeling and diversification benefits.

Key strengths: Privately held ownership structure insulates from public market volatility, Dominant market share in GIS software and spatial data platforms, Highly recurring subscription-based revenue model, Deep integration into government and enterprise critical infrastructure

Risk factors: Limited public financial transparency and auditability, Revenue concentration in a single core software category, Sensitivity to corporate and government IT budget cycles, Dependence on continuous R&D to maintain technological lead

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report