Internet Systems Consortium (ISC)

United States · www.isc.org · 16 vendors

Internet Systems Consortium (ISC) is a non-profit organization dedicated to developing software and offering services in support of the Internet infrastructure. It develops and distributes open-source internet networking software packages like BIND (DNS) and Kea DHCP, and operates the F-Root server, one of the 13 Internet root name servers.

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 16 sub-vendors.

Insights

Last updated 2026-07-30 · revision 6

16 direct vendors, 247 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

ISC exhibits medium migration readiness, characterized by strong technical foundations but tempered by regulatory complexities. A significant advantage for migration is the stated 'Total Vendors: 0', implying extremely low vendor lock-in and providing ISC with maximum flexibility and control over its technology stack for any migration initiatives. The product architecture, particularly Kea DHCP, is modern, multi-threaded, and features a REST API, JSON configuration, and support for database backends, making it well-suited for cloud-native deployments. The availability of official Docker images for BIND 9 and Kea, coupled with an internal tech stack that includes GitLab for CI/CD and modern programming languages (C++, Go, Angular/TypeScript), indicates a strong capability for containerization and cloud adoption. ISC also demonstrates a commitment to facilitating transitions by providing a Migration Assistant tool for moving from legacy ISC DHCP to Kea. However, migration readiness is moderately challenged by the 'Assessment Required' status for GDPR, SOC2, and ISO 27001. These unconfirmed compliance statuses, along with explicit acknowledgments of cross-border data transfers, mean that any migration strategy must meticulously address complex regulatory, data localization, and privacy requirements, particularly for international operations. While BIND 9 is a mature C-based application, its containerization via Docker images mitigates some of the legacy migration challenges. Financial stability is present, but the revenue profile suggests a measured approach to large-scale, potentially costly cloud migrations rather than rapid, extensive overhauls.

Compliance

3 in-scope frameworks identified; showing 3.

GDPR (source) — Assessment Required

ISC is US-based but operates globally with staff in 15 countries and serves international customers. They collect personal data from website visitors, mailing list subscribers, support customers, and employees. Their privacy policy acknowledges GDPR compliance obligations and mentions cross-border data transfers. Risk is medium due to potential EU operations and data processing of EU residents, but enforcement likelihood is moderate for a non-profit technical organization.

Evidence: https://www.isc.org/privacy

SOC 2 (source) — Assessment Required

ISC provides professional support services and operates critical internet infrastructure (F-Root). They handle customer data and provide cloud-based services. SOC2 compliance would be beneficial for their commercial support operations and infrastructure services, though enforcement risk is moderate for a non-profit organization.

Evidence: https://www.isc.org/support, https://www.isc.org/f-root

ISO 27001 (source) — Assessment Required

ISC operates critical internet infrastructure (F-Root) and handles sensitive customer data through support services. Information security management is crucial for their operations. Risk is medium due to the critical nature of their infrastructure role, though enforcement is typically voluntary for non-profit organizations.

Evidence: https://kb.isc.org/docs/aa-00861, https://www.isc.org/f-root

Financials

Three-year financials

Financial Resilience Score: 5/10

ISC operates as a small, stable, mission-driven 501(c)(3) non-profit at the core of global Internet infrastructure. Its recurring revenue model — built on annual software support contracts for BIND 9 and Kea DHCP — provides meaningful predictability, and its low capital intensity (primarily personnel costs across ~45 staff) keeps the cost structure lean and manageable. The organization's technical reputation, ubiquity of its software, and the mission-critical nature of DNS and DHCP infrastructure create a durable demand signal for its support services. However, ISC's financial resilience is structurally constrained by its small scale, with total revenue likely in the low single-digit millions of USD annually. The open-source free-rider dynamic — where the vast majority of BIND 9 and Kea users pay nothing — means revenue depends entirely on a small fraction of users voluntarily purchasing support contracts, a fragile conversion model. Revenue is also highly concentrated in just two software products, and the EOL of ISC DHCP introduces transition risk as customers may migrate to competitors rather than Kea DHCP. Competitive pressure from well-funded commercial vendors such as Infoblox and BlueCat, which offer integrated appliance-based DNS/DHCP solutions with managed services, poses a meaningful displacement risk in enterprise environments. Key-person and talent risk is elevated given the small, highly specialized team. Without confirmed access to Form 990 net asset data, the adequacy of ISC's financial reserves cannot be assessed, adding further uncertainty to the resilience score. Overall, ISC's resilience is moderate: its mission alignment, recurring contract revenue, and technical moat provide a stable foundation, but its small scale, open-source monetization challenges, product concentration, and unverified reserve position prevent a higher score.

Key strengths: Recurring annual software support contract revenue for BIND 9 and Kea DHCP, Low capital intensity — cost base is primarily personnel (salaries of ~45 engineers and support staff), Mission-critical software with deep global market penetration (BIND 9 is the world's most widely deployed DNS software), Non-profit status provides tax-exempt benefits and freedom from shareholder profit pressure, Strong technical reputation — ISC engineers have authored or co-authored over 100 Internet RFCs, Globally distributed team across 15 countries reduces single-country operational risk, Deliberate product modernization strategy (ISC DHCP EOL → Kea DHCP migration)

Risk factors: Small scale with revenue likely in low single-digit millions USD — limited financial buffer against shocks, Open-source free-rider problem: vast majority of users pay nothing; revenue depends on a small conversion fraction, High revenue concentration in two products: BIND 9 and Kea DHCP, ISC DHCP EOL transition risk — customers may migrate to commercial competitors rather than Kea, Competitive pressure from commercial DNS/DHCP vendors (Infoblox, BlueCat) offering integrated managed solutions, Key-person and talent risk in a small, highly specialized engineering team, No confirmed financial reserve data — adequacy of net assets cannot be assessed, Dependency on IANA/ICANN arrangements for F-Root operations, subject to policy changes

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report