European Space Agency

France · www.esa.int · 17 vendors

The European Space Agency (ESA) is an intergovernmental organization dedicated to space exploration and technology. It develops launchers, spacecraft, and ground facilities for Earth observation, navigation, telecommunications, astronomy, and human space exploration. ESA's mission is to shape Europe's space capability and ensure that investment in space benefits citizens globally.

Resilience scores

Disruption prediction

European Space Agency has an estimated 11% probability of disruption in the next 6 months.

9 of European Space Agency's 17 vendors monitored for disruptions.

Technology vendors

Services catalogue

3 services in catalogue across 1 category; runs on 17 sub-vendors.

Insights

Last updated 2026-06-10 · revision 1

17 direct vendors, 217 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

ESA exhibits a medium-high level of migration readiness, largely due to its significant adoption of modern, cloud-native technologies. The internal tech stack includes Docker, Kubernetes, AWS, Microsoft Azure, OpenStack, Apache Kafka, and REST APIs, indicating a strong foundation for cloud migration, containerization, and microservices architecture. The absence of specified data residency requirements is also a positive factor, potentially simplifying data relocation. However, several factors temper this readiness. The presence of traditional programming languages (C, C++), specialized engineering tools (MATLAB/Simulink, DOORS), and legacy databases (Oracle Database) suggests that some core systems may be monolithic or difficult to refactor, posing challenges for a complete cloud-native migration. The 'Unknown' vendor lock-in risk is a significant concern; while 21 services from vendors across 5 countries suggest some diversity, the degree of dependency and contract complexity are not specified, which could complicate vendor transitions. Additionally, the lack of financial stability data makes it impossible to assess ESA's capacity to fund a large-scale migration effort. Although not explicitly detailed, the highly regulated nature of the government and public sector, particularly in space operations, implies complex compliance requirements that would need careful navigation during any migration. Overall, while ESA has a strong technological foundation for migration, the unknowns regarding vendor lock-in, financial capacity, and potential legacy system complexities place its readiness in the moderate-to-high range.

Compliance

4 in-scope frameworks identified; showing 3.

GDPR (source) — Compliant

ESA demonstrates strong GDPR compliance with comprehensive Personal Data Protection Framework adopted in 2017 and updated in 2022. However, as a large international organization processing significant volumes of personal data across multiple EU member states, there remains medium risk due to the complexity of operations and potential for data breaches or processing errors. The organization has established proper governance with a Data Protection Officer and supervisory authority.

Evidence: https://www.esa.int/Services/Privacy_notice, https://www.esa.int/About_Us/Law_at_ESA/Highlights_of_ESA_rules_and_regulations

NIS2 (source) — Assessment Required

ESA operates critical space infrastructure including satellite systems, navigation services (Galileo), Earth observation systems, and space transportation systems that are essential for EU security and economic activities. As a space sector entity providing essential services across EU member states, ESA likely falls under NIS2 as an Essential Entity. Non-compliance could result in significant fines (up to €10M or 2% of annual turnover) and operational restrictions. The space sector is explicitly mentioned in NIS2 as critical infrastructure.

Evidence: https://www.esa.int/About_Us/Law_at_ESA/Highlights_of_ESA_rules_and_regulations

SOC 2 (source) — Assessment Required

ESA operates significant IT infrastructure, cloud services, and digital platforms for space missions, data processing, and public services. While not mandatory, SOC2 compliance would be valuable for demonstrating security controls to partners and stakeholders. Medium risk as lack of SOC2 certification could impact partnerships with US organizations or cloud service providers, but is not legally required.

Evidence: https://www.esa.int/About_Us/Law_at_ESA/Highlights_of_ESA_rules_and_regulations

Financials

Three-year financials

Financial Resilience Score: 9/10

ESA's financial resilience is exceptionally strong due to its nature as an intergovernmental organisation established by the 1975 ESA Convention. Its funding base is anchored in treaty commitments from 23 Member States with three-year Ministerial Council subscription envelopes, providing predictability far beyond what commercial entities can achieve. The trajectory of ministerial subscriptions (CM16 Lucerne ~€10.3B, CM19 Seville ~€14.4B, CM22 Paris ~€16.9B, CM25 Bremen ~€22.1B) demonstrates sustained 16-30% growth in commitment envelopes each cycle, evidencing strong and growing political backing. The annual budget has grown at ~5.7% CAGR from 2015 (€4.43B) to 2025 (€7.68B), with diversified funder base including 23 Member States, the EU (~28% via Copernicus, Galileo), Eumetsat, and third parties. The geo-return principle aligns industrial spending with contributions, sustaining political support. However, ESA cannot borrow, reserves are small relative to programme commitments, and ~25-30% dependence on EU-entrusted programmes creates structural risk if the EU shifts toward EUSPA or direct procurement. Programme cost overruns (Ariane 6, ExoMars) and geopolitical disruptions (loss of Soyuz launches after 2022 Ukraine invasion) have created cost pressures, but the overall financial profile remains highly stable.

Key strengths: Treaty-based funding from 23 Member States provides exceptional predictability, Three-year Ministerial Council subscription envelopes (CM25: ~€22.1B record subscription for 2026-2028), Diversified funder base: Member States (~64%), EU (~28%), Eumetsat/third parties (~8%), Sustained ~5.7% CAGR in annual budget over 2015-2025, Geo-return ('juste retour') principle aligns industrial spending with contributions, Strong political backing reflected in growing strategic autonomy interest

Risk factors: Programme cost overruns on long-duration programmes (Ariane 6, ExoMars), Dependence on EU framework programmes (~25-30% of annual budget), Competitive pressure from SpaceX/Starlink on launchers and telecommunications, Geopolitical disruption (loss of Soyuz launches at Kourou, ExoMars delays post-Ukraine invasion), ESA cannot borrow and reserves are small relative to programme commitments, Concentration of funding in top-3 contributors (Germany, France, Italy ~58-60%)

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report