Hardhat
Switzerland · hardhat.org · 3 vendors
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 5
- Financial Resilience: 4
Technology vendors
- Google LLC — Technology — United States
- MarketingPlatform ApS — Media & Marketing — Denmark
- Vercel Inc. — Technology — United States
Services catalogue
1 service in catalogue across 1 category; runs on 3 sub-vendors.
- Hardhat
Insights
Last updated 2026-07-07 · revision 1
3 direct vendors, 99 subvendors
Direct vendors by controlling owner country (sample)
- United States: 2
- Denmark: 1
Subvendors by controlling owner country (sample)
- Norway: 3
- Spain: 1
- United Kingdom: 4
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Hardhat demonstrates high migration readiness, primarily driven by its exceptionally modern and portable technology stack. The extensive use of TypeScript, Rust, Node.js, and WebAssembly (WASM) indicates a strong alignment with cloud-native principles. Their development environment, including GitHub Actions for CI/CD, is well-suited for modern DevOps practices and cloud deployments. The inherent nature of their products, focused on Ethereum development and EVM simulation, often involves distributed systems and leverages cloud infrastructure, suggesting a foundational understanding and capability for scalable, cloud-based operations. However, significant gaps in critical data introduce potential challenges. Information regarding the regulatory environment, specific data residency requirements, and the company's financial stability (which impacts the ability to fund a migration) is not provided. These factors can introduce substantial complexity, cost, and potential delays to any migration effort. Concerning vendor relationships, the data is contradictory, stating "Total Vendors: 0" but then detailing "Total Services: 4" from vendors in the United States and Denmark. Assuming the latter is relevant, Hardhat relies on a small number of services from external vendors. The "Vendor Lock-in Risk" is "Unknown," which could pose a challenge if these vendors are deeply integrated or have restrictive contracts. If "Total Vendors: 0" is strictly accurate, then vendor lock-in would not be a concern. Despite these unknowns, Hardhat's cutting-edge and highly adaptable tech stack positions it very favorably for migration. The primary challenges would stem from navigating potential regulatory or data residency constraints and managing any unforeseen vendor lock-in, rather than fundamental technological hurdles.
Compliance
6 in-scope frameworks identified; showing 3.
Blockchain — Assessment Required
Hardhat is a developer tooling environment — it does not issue tokens, operate exchanges, provide custody services, or offer financial services. As such, EU Markets in Crypto-Assets Regulation (MiCA) and Swiss FINMA crypto-asset regulations are unlikely to apply directly to Nomic Foundation. However, given the rapidly evolving regulatory landscape for blockchain infrastructure providers, an assessment is warranted to confirm that Hardhat's tooling role does not inadvertently trigger any regulatory obligations. Risk is Low because Hardhat is clearly a development tool, not a financial service.
Evidence: https://hardhat.org/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R1114
Cyber Resilience Act (source) — Assessment Required
The EU Cyber Resilience Act (CRA), adopted in 2024 and phasing in through 2027, introduces cybersecurity requirements for products with digital elements, including open-source software components used in commercial contexts. Hardhat is a widely-used open-source Ethereum development tool (8,500+ GitHub stars) that is integrated into commercial blockchain development workflows. The CRA includes provisions for open-source stewards. US Executive Order 14028 on Improving the Nation's Cybersecurity also emphasizes software supply chain security. Risk is Medium because: (1) Hardhat's widespread adoption means a supply chain compromise would have significant downstream impact; (2) the CRA's open-source steward obligations are still being defined; (3) no formal software bill of materials (SBOM) or supply chain security attestation has been publicly disclosed.
Evidence: https://github.com/NomicFoundation/hardhat, https://hardhat.org/
Swiss Federal Act on Data Protection — Partially Compliant
As a Swiss Foundation headquartered in Zug, Switzerland, Nomic Foundation is directly subject to the revised Swiss Federal Act on Data Protection (nFADP, in force since September 1, 2023). The Privacy Policy explicitly references both the FADP and OFADP. The foundation collects personal data from Swiss residents and globally. Risk is Medium because: (1) the nFADP introduced new obligations (data breach notification, privacy impact assessments, data protection advisor) that may not yet be fully implemented; (2) no formal nFADP compliance audit has been disclosed; (3) the foundation's Privacy Policy was last updated referencing the older FADP framework and may need updating for full nFADP alignment.
Evidence: https://hardhat.org/privacy-policy.html, https://www.fedlex.admin.ch/eli/cc/2022/491/en
Financials
Three-year financials
- null:
Financial Resilience Score: 4/10
Nomic Foundation, the entity behind Hardhat, is a Swiss non-profit Stiftung headquartered in Zug and does not publish financial statements publicly. As a result, standard financial metrics such as revenue, EBIT, equity, runway, and burn rate are not observable from open sources, making independent assessment of financial resilience impossible from public data alone. Any credit or supplier assessment should be conducted directly against the Nomic Foundation by requesting audited accounts. Qualitatively, the foundation benefits from a mission-critical position in the Ethereum developer tooling ecosystem, with Hardhat being one of the two dominant Solidity development frameworks. The non-profit foundation structure removes pressure to service equity investors and allows for a longer operational horizon funded by grants and ecosystem contributions, historically including support from the Ethereum Foundation. However, resilience is materially constrained by the absence of direct commercial revenue (the software is free and open-source), heavy dependence on ecosystem grants that correlate with crypto market cycles, and rising competitive pressure from Foundry which has taken developer mindshare. The organization is also highly concentrated on a single blockchain ecosystem (Ethereum/EVM), creating structural risk if Ethereum development activity declines. Given the opacity of financials, funder concentration, and cyclical grant dependence, resilience is rated as moderate-to-below-average despite strong product positioning.
Key strengths: Mission-critical product in Ethereum developer tooling niche, Non-profit Swiss foundation structure with no equity investor pressure, Historic backing from Ethereum Foundation and ecosystem donors, Active R&D momentum with Hardhat 3 released as production-ready in 2025, Strong ecosystem entrenchment among major DeFi and Web3 projects
Risk factors: No direct commercial revenue - product is free and open-source, Heavy dependence on external grants and donations, Competitive pressure from Foundry taking developer mindshare, Grant funding correlates with crypto market cycles creating volatility, Concentration risk on single blockchain ecosystem (Ethereum/EVM), Opacity of financials prevents independent assessment of runway and reserves, Funder concentration risk with heavy reliance on Ethereum Foundation
Revenue by product/service
- Hardhat Ignition (free/open-source): 0%
- Hardhat core framework (free/open-source): 0%
- Hardhat VS Code extension (free/open-source): 0%
- Ethereum Development Runtime/EDR (free/open-source): 0%
Workforce by country
- Argentina: 0
- Switzerland: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.