FM:Systems
United States · fmsystems.com · 25 vendors
FM:Systems provides Integrated Workplace Management Solutions (IWMS) that help facilities and real estate professionals optimize space management, enhance facility operations, and improve employee experiences. Their cloud-based platform offers solutions for hybrid work, space planning, facility maintenance, and workplace analytics.
Resilience scores
- Digital Sovereignty: 52
- Digital Resilience: 9
- Financial Resilience: 8
Technology vendors
- Demandware — Technology — United States
- Rain-Task Limited — Technology — United Kingdom
- Sage Intacct — Technology — United States
- and 22 more
Services catalogue
1 service in catalogue across 1 category; runs on 25 sub-vendors.
- Integrated Workplace Management System
Insights
Last updated 2026-08-11 · revision 2
25 direct vendors, 247 subvendors
Direct vendors by controlling owner country (sample)
- Australia: 3
- United States: 13
- UK: 1
Subvendors by controlling owner country (sample)
- Brazil: 1
- Netherlands: 4
- Poland: 2
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
FM:Systems exhibits high migration readiness, largely due to its advanced and predominantly cloud-native technology stack. The company extensively utilizes Microsoft Azure (with FedRAMP authorization) and Amazon Web Services (AWS), demonstrating a strong foundation in cloud infrastructure and multi-cloud operational experience. The adoption of IoT/MQTT protocols, REST APIs, and a "Cloud-Based SaaS Platform" suggests a modular and API-driven architecture, which significantly eases the process of migrating components or integrating with new systems. FedRAMP authorization is a key enabler, indicating that the company already adheres to stringent security and compliance standards, which streamlines migration to other regulated or compliant environments. The use of modern solutions like "Integrated Workplace Management System (IWMS)" and "Digital Twin / Interactive Floorplans" further points to a flexible and adaptable system. However, several factors introduce uncertainty: data residency requirements are not specified, which could pose challenges depending on the target migration environment; financial stability data is unavailable, making it difficult to assess the capacity to fund a large-scale migration; and while vendor geographic diversity is present across 8 countries for their 35 services, the specific vendor lock-in risks and complexity of migrating these numerous service dependencies remain unknown.
Compliance
8 in-scope frameworks identified; showing 3.
POPIA — Assessment Required
FM:Systems has a confirmed office in Johannesburg, South Africa (42 Bath Ave, Rosebank). South Africa's POPIA (effective July 2021) applies to responsible parties that process personal information of data subjects in South Africa. As an established entity in South Africa, FM:Systems is directly subject to POPIA for personal data processed in connection with its South African operations (employees, customers, visitors). Risk is Medium because: (1) POPIA is enforced by the Information Regulator of South Africa with fines up to ZAR 10M or imprisonment; (2) FM:Systems' South African office processes employee personal data at minimum; (3) if FM:Systems serves South African customers through its local office, customer data processing is also subject to POPIA; (4) enforcement has been increasing since the grace period ended in 2021.
Evidence: https://fmsystems.com/about-us/
SOC 2 (source) — Assessment Required
FM:Systems is a cloud-based SaaS provider serving 1,200+ enterprise customers across 80+ countries, including government agencies, financial institutions, healthcare organizations, and large corporations. SOC 2 is the de facto standard for cloud service providers in the US market, and enterprise customers — particularly in government, finance, and healthcare — routinely require SOC 2 Type II reports as part of vendor due diligence. Risk is Medium because: (1) the absence of publicly disclosed SOC 2 certification for a SaaS company of this scale serving regulated industries is a notable gap; (2) enterprise customers may be contractually requiring SOC 2 reports that are shared under NDA (not publicly visible); (3) FedRAMP authorization (achieved April 2025) demonstrates a higher security bar than SOC 2 and covers NIST SP 800-53 controls, which significantly overlaps with SOC 2 Trust Service Criteria; (4) without confirmed SOC 2 Type II, there is residual risk in customer procurement processes and potential contract non-compliance.
Evidence: https://fmsystems.com/news/fmsystems-workplace-management-fedramp-authorized/, https://www.johnsoncontrols.com/trust-center/cybersecurity, https://fmsystems.com/industries/government/, https://fmsystems.com/industries/finance/
GDPR (source) — Assessment Required
FM:Systems has confirmed office operations in the UK (Blackburn and Woking/Surrey), Bulgaria (Sofia — an EU member state), and South Africa, and serves customers in 80+ countries including EU/EEA markets. Its SaaS platform processes personal data of employees, visitors, and occupants on behalf of EU-based customers, making it a data processor under GDPR. Its visitor management, desk booking, occupancy sensor, and employee experience products inherently handle personal data (names, location data, booking records, biometric/sensor data). As a subsidiary of Johnson Controls — a global corporation with extensive EU operations — GDPR obligations are pervasive. Non-compliance risk is High due to: (1) potential fines up to €20M or 4% of global annual turnover; (2) the company's Bulgarian office places it directly within EU jurisdiction as an establishment; (3) the scale of personal data processing across 80+ countries; (4) enforcement by EU DPAs has intensified significantly since 2022. Johnson Controls' Trust Center references a Global Privacy Notice, cross-border data transfer mechanisms, and TRUSTe certifications, indicating awareness, but FM:Systems-specific GDPR compliance documentation (DPA agreements, DPO appointment, Article 30 records) is not publicly confirmed.
Evidence: https://fmsystems.com/about-us/, https://www.johnsoncontrols.com/trust-center/privacy, https://www.johnsoncontrols.com/trust-center/privacy/global-privacy-notice, https://www.johnsoncontrols.com/trust-center/privacy/cross-border-data-transfers, https://www.johnsoncontrols.com/trust-center/privacy/data-privacy-sheets
Financials
Three-year financials
- 2023:
- 2022:
- 2021:
Financial Resilience Score: 8/10
FM:Systems' financial resilience is materially strengthened by its July 2023 acquisition by Johnson Controls International (NYSE: JCI), an investment-grade parent with approximately US$27B in annual revenue. This ownership structure effectively removes liquidity, working capital, and financing concerns that existed during its prior PE-owned standalone period under Accel-KKR. The base acquisition price of US$455M plus undisclosed earnout suggests the business had meaningful scale and growth momentum at the time of the deal. The underlying business model is a recurring SaaS revenue stream from IWMS software subscriptions, sensor-as-a-service, and analytics, serving 1,200+ customers across 80+ countries with 3B+ sq ft managed and 250,000+ deployed sensors. Blue-chip customer references (JLL, Samsung, Sysco, Southwest Airlines) and Deloitte Technology Fast 500 recognition in 2022 (implying 3-year growth of ≥135%) indicate healthy pre-acquisition growth. The April 2025 FedRAMP Authorization unlocks US federal government sales, providing an additional growth vector. However, no specific financial figures (revenue, EBIT, equity) are publicly disclosed either as a standalone entity historically or as a subsidiary within JCI's segment reporting, creating opacity for external stakeholders. The business is also exposed to cyclical office real estate demand and hybrid-work trends, and operates in a crowded IWMS/workplace-experience market with competitors including IBM TRIRIGA, Planon, Archibus/Eptura, MRI Software, Nuvolo, Envoy, Robin, and OfficeSpace.
Key strengths: Backed by investment-grade parent Johnson Controls (~US$27B revenue), Recurring SaaS revenue model with strong retention metrics, 1,200+ customers across 80+ countries, 3B+ sq ft managed, Blue-chip customer base (JLL, Samsung, Sysco, Southwest Airlines), FedRAMP Authorization (April 2025) unlocks federal government sales, Deloitte Technology Fast 500 (2022) - implies ≥135% 3-year growth, Cross-sell leverage with JCI OpenBlue platform and global channels, 40-year operating history (founded 1984)
Risk factors: Sensitivity to office real estate demand and hybrid-work trends, Highly competitive IWMS market (TRIRIGA, Planon, Eptura, MRI, Nuvolo, Envoy, Robin), Integration and attrition risk post-acquisition, Opacity - no public financial disclosures at subsidiary level, Concentration in mid-to-large enterprise with long, capex-linked sales cycles
Revenue by geography
- APAC: 0%
- EMEA: 0%
- North America: 0%
Revenue by product/service
- OpenBlue Workplace (IWMS core): 0%
- OpenBlue Employee (hybrid-work): 0%
- OpenBlue Insights (analytics & sensors): 0%
Workforce by country
- United States: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.