Hosting.de GmbH

Germany · www.hosting.de · 8 vendors

Resilience scores

Technology vendors

Services catalogue

4 services in catalogue across 1 category; runs on 8 sub-vendors.

Insights

Last updated 2026-07-06 · revision 7

8 direct vendors, 103 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Hosting.de GmbH exhibits a medium-to-high level of migration readiness, scoring 65. A significant advantage is the reported 'Total Vendors: 0', which implies a lack of external vendor lock-in. This dramatically simplifies the process of migrating services without needing to untangle complex vendor contracts or dependencies. The company's financial stability, evidenced by recent growth and investment in capacity expansion, suggests it has the resources to fund a significant migration effort. The proprietary REST API, described as an 'API-first approach,' is a strong enabler for programmatic management and integration, which would facilitate automated migration and integration with new platforms. The existing ISO 27001 certification provides a robust security framework that can be leveraged to ensure a secure migration process. However, several factors present challenges. The most significant is the strict German/EU data residency requirement, explicitly stated as 'Hosting in Deutschland' and 'DSGVO-konform'. This severely limits the choice of target environments, as any new infrastructure must guarantee data localization within Germany or the EU, potentially excluding many global public cloud regions. While the tech stack is modern for a hosting provider, the use of C++ and Qt Framework, without explicit mention of containerization or microservices, suggests a potentially more monolithic or custom-built internal architecture that might require significant refactoring for a cloud-native migration. Lastly, while GDPR and ISO 27001 are strong, the 'Assessment Required' status for NIS2 and SOC2 could introduce additional compliance hurdles or requirements during a migration, adding complexity and potential delays.

Compliance

7 in-scope frameworks identified; showing 3.

ISAE 3000 (source) — Assessment Required

ISAE 3000 is an international assurance standard used for non-financial assurance engagements, often applied in the context of third-party assurance reports on controls (similar to SOC 2 but under IAASB standards). It is most commonly required by large enterprise customers, financial institutions, or regulated industries seeking independent assurance over service provider controls. Hosting.de GmbH is a small-to-medium German hosting provider (~36 employees) primarily serving SMEs, freelancers, and agencies. Risk is Low because: (1) ISAE 3000 reports are not a standard requirement in the German SME hosting market; (2) the company's ISO 27001 certification provides equivalent or superior assurance for most customer requirements; (3) the company's customer base (SMEs, freelancers, agencies) typically does not require ISAE 3000 attestations; (4) no evidence of customer demand for ISAE 3000 reports has been identified.

Evidence: https://www.hosting.de/ueber-uns/iso-certification/

ISO 27001 (source) — Compliant

Hosting.de GmbH explicitly claims and promotes ISO/IEC 27001 certification across its website, including in the meta description ('DSGVO-konform und ISO27001-zertifiziert'), on the homepage, on a dedicated ISO certification page, and in the website footer. The company describes a full certification process including gap analysis, ISMS implementation, staff training, internal audits, and external audit by an accredited certification body. Risk is Low because: (1) the certification is actively maintained and promoted as a core business differentiator; (2) ISO 27001 requires annual surveillance audits and triennial recertification, indicating ongoing commitment; (3) the certification directly supports GDPR compliance and NIS2 readiness; (4) the company's business model (hosting sensitive customer data) creates strong commercial incentive to maintain certification.

Evidence: https://www.hosting.de/ueber-uns/iso-certification/, https://www.hosting.de/, https://www.hosting.de/ueber-uns/datenschutz/

BDSG — Compliant

The BDSG is the German national data protection law that supplements and implements GDPR in Germany. It applies to all German companies processing personal data. Hosting.de GmbH is a German GmbH and must comply with BDSG in addition to GDPR. Risk is Low because: (1) the company's GDPR compliance programme (DPO, privacy policy, lawful bases) inherently addresses BDSG requirements; (2) the company explicitly references the LDI NRW as its supervisory authority, demonstrating awareness of German data protection law; (3) BDSG-specific provisions (e.g., employee data protection, SCHUFA credit checks under §31 BDSG) are addressed in the privacy policy; (4) the company's ISO 27001 certification supports BDSG technical and organisational measures.

Evidence: https://www.hosting.de/ueber-uns/datenschutz/, https://www.hosting.de/

Financials

Three-year financials

Financial Resilience Score: 7/10

hosting.de GmbH is a well-established, mid-sized German managed hosting provider with a 20-year operating history and a recurring subscription-based revenue model that provides predictable cash flows and low churn typical of the hosting industry. The company is vertically integrated with its own data centres in Aachen, Cologne, and Nuremberg, a proprietary C++/Qt platform, and in-house API, which reduces dependency on third-party vendors and preserves margins. It self-reports being '100% Eigenkapital' (fully equity-financed) at the operating entity level, and since 2022 is part of the Namespace Group, a Central-European hosting consolidator providing scale, funding access, and cross-selling opportunities. Regulatory positioning is strong with ISO 27001 certification, GDPR compliance, and Nextcloud Gold Partner status. However, the company is small (~36 employees) and competes with much larger players (1&1 IONOS, Strato, Hetzner, Hosteurope) with 10-100x the workforce, limiting pricing power and R&D absorption. Recent capex intensity (2023 data centre migration, 2019 network upgrade to 100 Gbit/s) pressures free cash flow, and core products face commoditisation pressure. Geographic concentration in Germany is high, with only a nascent 2025 France expansion. As a small GmbH, no P&L is publicly disclosed, limiting external financial visibility. The successful strategic sale to Namespace Group in 2022 signals a healthy, sellable subscription business.

Key strengths: Recurring subscription revenue model (hosting, domains, mail, DNS, SSL), 20-year operating history with steady organic growth, Vertical integration with own data centres and proprietary platform, Self-reported 100% equity-financed at operating entity level, Backing by Namespace Group since 2022 (strategic owner with scale), ISO 27001 certified, GDPR-compliant, 'made in Germany' positioning, 30,000+ customers, 300,000+ domains, ~2,000 servers

Risk factors: Small scale (~36 employees) vs. much larger competitors (1&1 IONOS, Strato, Hetzner), Capex intensity from data centre migration and network upgrades, Commoditisation of core products (domains, shared hosting), High geographic concentration in Germany, Ownership complexity under Namespace Group consolidator (potential cash sweeps), Financial opacity - no public P&L disclosure as small GmbH

Revenue by geography

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report