Internet Testing Systems

United States · www.testsys.com · 10 vendors

Internet Testing Systems (ITS) crafts dynamic web-based solutions that empower certifying organizations to seamlessly manage their assessments. The company provides complete online solutions for the management, delivery, and reporting of assessment programs across various sectors including healthcare, IT, academic, and professional assessments.

Resilience scores

Technology vendors

Insights

Last updated 2026-07-30 · revision 1

10 direct vendors, 157 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Internet Testing Systems shows high migration readiness, primarily driven by its modern technological foundation and the interpretation of vendor relationships. The internal tech stack includes 'cloud/AI infrastructure' and key technologies like 'AI/ML (SparkAI™)', 'generative AI', and 'machine learning', indicating a likely compatibility with cloud-native architectures and modern migration strategies. A significant strength for migration readiness is the explicit data point 'Total Vendors: 0'. Interpreting this literally, the company has no external vendors, which effectively eliminates vendor lock-in as a migration hurdle, providing immense flexibility. However, there are critical gaps in the available data that introduce uncertainty. The 'Regulatory Environment' is not specified, meaning potential compliance requirements that could complicate migration are unknown. Similarly, 'Data Residency Requirements' are 'Not specified', which is a crucial unknown that could significantly impact migration strategy and complexity. Lastly, the absence of financial stability data (revenue concentration, growth history) makes it impossible to assess the company's financial capacity to fund a potentially large migration effort.

Compliance

7 in-scope frameworks identified; showing 3.

GDPR (source) — Partially Compliant

ITS has taken meaningful steps toward GDPR compliance — publishing a dedicated GDPR Statement, certifying under the EU-U.S. Data Privacy Framework (DPF), executing Standard Contractual Clauses (SCCs) with EU/UK partners, and acknowledging its role as a data processor under Article 28. However, risk remains at Medium because: (1) data is stored exclusively in the US with no EU data residency option disclosed, which may conflict with some partners' GDPR obligations; (2) no independent third-party GDPR audit or DPA registration evidence is publicly available; (3) ITS operates across 230 countries/territories, meaning the volume and diversity of EU personal data processed is substantial; (4) as a processor, ITS inherits compliance obligations from controllers and any gap in SCC coverage or DPF validity (the DPF has faced legal challenges historically) creates residual risk; (5) breach notification timelines are contractually variable rather than fixed at the GDPR-mandated 72 hours. Fines under GDPR can reach €20M or 4% of global annual turnover.

Evidence: https://www.testsys.com/gdpr/, https://www.testsys.com/privacy-policy/, https://www.dataprivacyframework.gov/, https://www.testsys.com/ccpa-statement/

CPRA — Partially Compliant

ITS has published a dedicated CCPA Statement on its website, demonstrating awareness and active compliance efforts. Risk is Medium because: (1) ITS operates as a US-based company serving clients nationwide, including California residents who take assessments; (2) CCPA/CPRA applies to businesses meeting revenue/data thresholds that collect personal information of California consumers; (3) the published CCPA Statement indicates compliance intent but no independent audit or enforcement action history is available; (4) CPRA (effective 2023) introduced additional requirements (data minimization, purpose limitation, sensitive personal information rights) that may require updates to ITS's practices; (5) California AG and CPPA enforcement has been active.

Evidence: https://www.testsys.com/ccpa-statement/, https://www.testsys.com/privacy-policy/, https://cppa.ca.gov/

FERPA — Assessment Required

ITS explicitly serves academic institutions and educational testing organizations, including ETS (Educational Testing Service) and ERB (Educational Records Bureau). FERPA protects the privacy of student education records at institutions receiving federal funding. If ITS processes education records on behalf of educational institutions or testing organizations that serve K-12 or higher education students, FERPA may apply. Risk is Medium because: (1) academic sector is explicitly served; (2) ETS and ERB are major educational assessment organizations; (3) FERPA violations can result in loss of federal funding for educational institutions; (4) as a service provider/contractor, ITS may be subject to FERPA's 'school official' exception requirements.

Evidence: https://www.testsys.com/, https://www.testsys.com/markets-we-serve/, https://studentprivacy.ed.gov/ferpa

Financials

Three-year financials

Financial Resilience Score: 7/10

Internet Testing Systems (ITS) is a stable, founder-led private LLC with an ~28-year operating history in the online assessment industry. Despite the absence of public financial statements, multiple qualitative indicators suggest resilience: long executive tenure (18-26 years for several C-suite members), blue-chip customer relationships (ETS, Pearson VUE, GMAC, Certiport, Microsoft, ABMS, ERB), and a diversified product suite spanning test delivery, item authoring, remote proctoring, and AI-enabled solutions. The company delivers approximately 26 million tests annually across 230 countries and 60 languages, indicating meaningful scale. The recent selection to power the NextGen Bar Exam is a marquee multi-year contract that likely adds material revenue and reference value. Certification/credentialing testing typically operates under multi-year contracts with high switching costs, providing revenue visibility. Employee stability (average tenure ~8.5 years, 36 employees with 15+ years) is unusually high for the tech sector and signals a healthy operating culture. However, resilience is constrained by zero public financial transparency, competition from much larger and better-capitalized rivals (Pearson VUE, Prometric, PSI Services, Meazure Learning), potential customer concentration risk, key-person/founder-family governance concentration (Pat Ward CEO, Lisa Ward COO), and the need for sustained R&D spending to counter AI-driven cheating threats and evolving compliance requirements. As a private LLC, growth capital access is limited to cash flow, bank debt, or private equity.

Key strengths: Founder-led with 28-year operating history (since 1997), Blue-chip customer roster: ETS, Pearson VUE, GMAC, Certiport, Microsoft, ABMS, ERB, Long-tenured executives (18-26 years) and workforce (avg 8.5 years), Recurring-revenue model with multi-year contracts and high switching costs, Recent NextGen Bar Exam contract win, Diversified product suite (test delivery, proctoring, item authoring, AI), ~26 million tests delivered annually across 230 countries, ~50,000 hours of R&D per year (self-reported)

Risk factors: Zero public financial transparency (private LLC, no SEC filings), Competition from larger, better-capitalized rivals (Pearson VUE, Prometric, PSI Services), Potential customer concentration risk (unquantified), Founder/family concentration in leadership (key-person risk), Technology transition risk from generative AI in cheating tools, Limited access to public capital markets as private LLC, Evolving compliance requirements (GDPR, CCPA), Industry consolidation risk

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report