GMO Internet Group, Inc.

Japan · www.gmo.jp · 12 vendors

Resilience scores

Technology vendors

Services catalogue

6 services in catalogue across 3 categories; runs on 12 sub-vendors.

Insights

Last updated 2026-08-04 · revision 2

12 direct vendors, 245 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

GMO Internet Group exhibits very high migration readiness, scoring 90 out of 100. This is primarily driven by its highly advanced and cloud-native internal tech stack. The company has adopted a multi-cloud strategy, utilizing AWS, Google Cloud Platform, and Microsoft Azure, which inherently reduces vendor lock-in and provides flexibility for workload migration. The extensive use of containerization technologies like Kubernetes and Docker, coupled with modern development practices such as SRE, indicates a microservices-oriented architecture that is highly portable and scalable. Their proficiency in modern languages (Python, Go, TypeScript) and engagement with LLM/Generative AI tooling further underscore a forward-thinking and agile development environment. While the 'Total Vendors: 0' data point is confusing, the company's multi-cloud adoption and use of open-source technologies (Kubernetes, Docker, OpenStack) suggest a low dependency on proprietary, monolithic systems, thereby minimizing vendor lock-in risks for migration. The geographic diversity of implied vendors (United States, Japan, Denmark) also contributes positively to managing external dependencies. Key challenges and opportunities for migration are not fully assessable due to missing information regarding specific regulatory environments, data residency requirements, and financial stability to fund large-scale migration initiatives. However, the technical foundation is exceptionally strong for efficient and flexible migration efforts.

Compliance

8 in-scope frameworks identified; showing 3.

Japan Payment Services Act — Assessment Required

GMO Internet Group operates in internet finance (GMO Payment Gateway, GMO Financial Gate, GMO Aozora Net Bank) and cryptocurrency (GMO Coin, GMO Mining) sectors, both of which are subject to stringent FSA regulation in Japan. The Payment Services Act governs fund transfer services, prepaid payment instruments, and cryptocurrency exchange operators. GMO Aozora Net Bank is a licensed bank subject to the Banking Act. GMO Payment Gateway (listed, TSE Prime: 3769) is a major payment processor. GMO Financial Holdings (TSE Standard: 7177) operates FX and securities businesses. The high risk level reflects: (1) Multiple regulated financial entities within the group; (2) Cryptocurrency regulation under the amended Payment Services Act (2020, 2023 amendments); (3) Banking regulation for GMO Aozora Net Bank; (4) Potential exposure to AML/CFT (Anti-Money Laundering/Counter-Terrorism Financing) requirements under the Act on Prevention of Transfer of Criminal Proceeds.

Evidence: https://group.gmo/service/search/3/, https://group.gmo/service/search/4/, https://group.gmo/csr/governance/compliance/, https://group.gmo/company-profile/groupinfo/

ISO 27001 (source) — Assessment Required

GMO Internet Group has established a formal Information Security Management System (ISMS) as documented in its Information Security Basic Policy (established 2017-01-01). The policy explicitly references operating, reviewing, maintaining, and improving an ISMS — language directly aligned with ISO 27001 requirements. As a major internet infrastructure and security services provider with 7,936 employees and multiple listed subsidiaries, ISO 27001 certification is a strong market expectation. Individual subsidiaries (particularly GMO GlobalSign as a CA, and GMO Payment Gateway) are likely to hold ISO 27001 certifications. Risk is Medium because the ISMS framework is documented but no certification evidence was found at the group holding company level.

Evidence: https://group.gmo/terms/infosecurity/, https://group.gmo/csr/governance/, https://group.gmo/company-profile/outline/

GDPR (source) — Assessment Required

GMO Internet Group is headquartered in Japan (not EU/EEA), but operates globally with subsidiaries and services that likely reach EU/EEA residents. Key subsidiaries such as GMO GlobalSign (a major SSL/TLS certificate authority with European operations) and GMO Payment Gateway have documented European customer bases. The group's internet infrastructure, domain registration (onamae.com), and cloud/hosting services are accessible to EU residents. As a large-scale internet services conglomerate with 7,936 employees and multiple listed subsidiaries, the likelihood of processing EU personal data is high. However, no formal GDPR compliance certification, DPO appointment, or EU representative disclosure was found on the public website. The privacy policy (last revised 2025-09-10) references Japanese law (Act on the Protection of Personal Information) but does not explicitly address GDPR obligations. Risk is Medium rather than High because the company is Japan-based and primary operations are domestic, but the extraterritorial reach of GDPR to non-EU companies offering services to EU residents creates meaningful exposure.

Evidence: https://group.gmo/csr/governance/privacy-policy/, https://group.gmo/terms/infosecurity/, https://group.gmo/company-profile/outline/, https://group.gmo/company-profile/groupinfo/

Financials

Three-year financials

Financial Resilience Score: 7/10

GMO Internet Group demonstrates strong financial resilience underpinned by a diversified internet conglomerate structure spanning infrastructure, security, advertising/media, financial services, and crypto assets. The company has posted consistent revenue growth over five years (¥241.6B to ¥285.6B, CAGR ~4.3%) and expanding operating income (CAGR 8.6%), with a particularly strong FY2025 operating margin of ~20%. Recurring subscription-like revenue from hosting, domains, SSL, and payment processing provides a stable base, while payment transaction volume nearly tripled from ¥8.7T to ¥22.8T between 2021 and 2025. Cash generation is robust, with free cash flow of approximately ¥54B in both FY2024 and FY2025, supporting dividends, buybacks, and CapEx including AI/GPU-cloud investment. Shareholders' equity grew 55% over five years and ROE remains healthy in the mid-to-high teens. Ten subsidiaries are separately listed on the TSE, providing multiple capital-market access points and market-based valuations. However, the balance sheet shows total assets of ¥2.27T against equity of only ¥217B (equity ratio ~9.6%), reflecting customer deposits and margin balances at regulated financial subsidiaries (GMO Aozora Net Bank, GMO Click, GMO Coin). This creates sensitivity to market volatility, interest-rate movements, and crypto price cycles. FX trading volumes have historically been lumpy, and heavy recent CapEx on AI infrastructure has yet to prove returns.

Key strengths: Diversified five-segment internet conglomerate structure, Recurring subscription revenue with 19.0M hosting/infrastructure contracts, Payment transaction volume tripled to ¥22.8T (2021-2025), Strong free cash flow (~¥54B in FY2024 and FY2025), Equity grew 55% over five years; ROE in mid-to-high teens, Ten TSE-listed subsidiaries provide capital market access, Operating margin expanded to ~20% in FY2025, Consistent revenue growth for over a decade

Risk factors: Low equity ratio of ~9.6% due to financial subsidiary deposits, Crypto-asset exposure creates earnings volatility, FX/brokerage trading volumes are highly cyclical, Heavy recent CapEx (¥22-31B) on AI/GPU with unproven returns, Complex group structure creates minority-interest volatility, Concentration in Japanese market, Regulatory exposure from FSA-regulated financial subsidiaries

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report