Gandi SAS
France · www.gandi.net · 31 vendors
Gandi SAS is a French company specializing in domain name registration, web hosting, and related internet services. It provides SSL certificates, cloud infrastructure, and corporate domain management solutions. The company serves a global customer base, focusing on ethical internet practices and customer privacy.
Resilience scores
- Digital Sovereignty: 16
- Digital Resilience: 7
Technology vendors
- Netlify, Inc. — Technology — United States
- Open-Xchange AG — Technology — Germany
- Stripe, Inc. — Financial Services — United States
- and 28 more
Services catalogue
7 services in catalogue across 4 categories; runs on 31 sub-vendors.
- Anycast DNS
- Domain Registration
- Gandi DNS
Insights
Last updated 2026-03-13 · revision 1
31 direct vendors, 256 subvendors
Direct vendors by controlling owner country (sample)
- United States: 23
- Germany: 2
- Sweden: 2
Subvendors by controlling owner country (sample)
- United Kingdom: 6
- Canada: 8
- Bulgaria: 1
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Gandi SAS exhibits strong migration readiness, primarily driven by its modern technical foundation. The company extensively uses Infrastructure-as-Code (IaC) tools like Terraform and Ansible, along with Cloud-init, which are essential for automating infrastructure provisioning and management in a cloud migration scenario. Their experience with OpenStack, an IaaS cloud platform, suggests familiarity with cloud concepts and operations. The availability of a public RESTful API for managing all Gandi products is a significant enabler for programmatic migration and integration with new cloud environments. Furthermore, existing ISO 27001:2022 ISMS certification and GDPR compliance streamline the regulatory aspects of migrating data and services to compliant cloud providers. However, certain unknowns pose potential challenges. Data residency requirements are not specified; if strict requirements exist, they could complicate the choice of cloud providers and migration strategy. The company's financial stability (revenue, growth history) is not provided, making it difficult to assess the budget available for a potentially costly migration effort. The vendor relationship data is contradictory, stating "Total Vendors: 0" but also listing "Total Services: 47" and diverse vendor geographies. While the geographic diversity of vendor HQ countries (7 unique countries) is a positive, the actual number of unique vendors and the specific vendor lock-in risk are unknown. This lack of clarity on vendor concentration makes it challenging to fully assess the complexity of disentangling from existing dependencies during a migration.
Compliance
5 in-scope frameworks identified; showing 3.
Digital Services Act — Compliant
Gandi demonstrates active DSA compliance as an intermediary service provider with published transparency reports, content moderation procedures, and cooperation with EU authorities. They handle notifications and takedown requests efficiently (median 1.7 hours response time).
Evidence: https://www.gandi.net/en/digital-service-act-transparency-report
NIS2 (source) — Assessment Required
Gandi operates in the digital infrastructure sector (domain registration, web hosting, cloud services) which falls under NIS2 scope as 'digital providers' (Important Entities). With 150+ employees and significant operations, they likely exceed size thresholds. However, specific NIS2 compliance status is not publicly disclosed, requiring formal assessment.
Evidence: https://www.gandi.net/en/about-us
ISO 27001 (source) — Compliant
Gandi holds current ISO 27001:2022 certification from BSI (Certificate IS 800630, valid until 2027-05-12). This demonstrates strong information security management system implementation. Risk is low due to active certification and comprehensive security framework.
Evidence: https://www.gandi.net/static/documents/Gandi_ISO_27001_certificate.pdf, https://www.gandi.net/en/trust-center
Financials
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.