iquer.net GmbH & Co KG
Germany · www.iquer.net · 10 vendors
Resilience scores
- Digital Sovereignty: 30
- Digital Resilience: 7
- Financial Resilience: 6
Technology vendors
- Cegedim SA — France
- Qode Interactive — Serbia
- Rain-Task Limited — Technology — United Kingdom
- and 8 more
Services catalogue
1 service in catalogue across 1 category; runs on 10 sub-vendors.
- iquer.net Web Hosting
Insights
Last updated 2026-07-27 · revision 2
10 direct vendors, 115 subvendors
Direct vendors by controlling owner country (sample)
- Germany: 1
- United Kingdom: 1
- India: 1
Subvendors by controlling owner country (sample)
- France: 11
- Switzerland: 1
- Canada: 2
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
iquer.net demonstrates a very high level of migration readiness, primarily driven by its sophisticated and modern internal tech stack. The extensive use of containerization technologies like Docker and Kubernetes, coupled with robust CI/CD pipelines via GitLab/GitLab CI, signifies a strong capability for developing and deploying cloud-native applications. Their expertise in virtualization (Proxmox, Virtuozzo, KVM), distributed storage (Ceph, OpenZFS), and configuration management (Puppet) provides a solid foundation for efficient lift-and-shift or re-platforming strategies to various cloud environments. The company's experience with a wide range of operating systems and databases further enhances its flexibility for migration projects. The geographic diversity of their vendor base (9 countries) also suggests a reduced overall risk of vendor lock-in, assuming favorable contract terms. Key information gaps hinder a complete assessment. The absence of data on the regulatory environment and specific data residency requirements is a significant concern, as these factors are paramount for cloud migration, especially for a German company operating under GDPR. Without this information, potential compliance hurdles and architectural constraints cannot be fully evaluated. Additionally, the lack of financial stability data (revenue concentration, growth history) makes it impossible to assess the company's capacity to fund a potentially substantial migration initiative. The specific details of vendor lock-in risk, beyond geographic diversity, also remain unknown.
Compliance
10 in-scope frameworks identified; showing 3.
KRITIS — Assessment Required
Germany's KRITIS regulation (BSI-Gesetz + BSI-KritisV) imposes cybersecurity obligations on operators of critical infrastructure. iquer.net itself, with revenue of ~€1.4M, is unlikely to meet the KRITIS thresholds for digital infrastructure operators (which require serving a significant portion of the German population). However, iquer.net serves clients that ARE KRITIS operators (Stadtwerke Gütersloh – energy/utilities, healthcare providers), which creates indirect supply chain security obligations. Risk is Low for direct KRITIS applicability, but Medium for supply chain security obligations to KRITIS clients.
Evidence: https://www.iquer.net/unternehmen/, https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Kritische-Infrastrukturen/kritis_node.html, https://www.gesetze-im-internet.de/bsig_2009/
ISO 27001 (source) — Assessment Required
iquer.net explicitly states on its hosting page that its datacenters are ISO 27001 certified ('nach ISO27001 und PCI DSS zertifiziert'). However, this refers to the datacenter facilities used, not necessarily to iquer.net GmbH & Co KG as a company holding its own ISO 27001 certification. The distinction is important: a company can operate in ISO 27001-certified facilities without itself being ISO 27001 certified. For a managed services and hosting provider serving enterprise and regulated-industry clients, company-level ISO 27001 certification is a significant competitive differentiator and may be contractually required by clients. Risk is Medium because: the datacenter-level certification provides partial assurance, but the absence of a company-level ISO 27001 certificate represents a gap that could affect enterprise client acquisition and retention, particularly in regulated sectors (healthcare, finance).
Evidence: https://www.iquer.net/hosting/, https://www.iso.org/isoiec-27001-information-security.html
PCI DSS (source) — Assessment Required
iquer.net's hosting page explicitly states that its datacenters are 'nach ISO27001 und PCI DSS zertifiziert' (ISO 27001 and PCI DSS certified). This indicates that the datacenter infrastructure meets PCI DSS requirements. However, as with ISO 27001, this is datacenter-level certification. If iquer.net hosts e-commerce or payment processing applications for clients (which is plausible given its client base including Suzuki, Bausch & Lomb, and retail/commercial clients), iquer.net may have obligations as a PCI DSS service provider. Risk is Medium because: the datacenter certification provides a strong foundation, but the company's own PCI DSS service provider status and compliance level are unclear.
Evidence: https://www.iquer.net/hosting/, https://www.pcisecuritystandards.org/
Financials
Three-year financials
- null: revenue EUR 1.4M
Financial Resilience Score: 6/10
iquer.net GmbH & Co KG demonstrates qualitative signs of financial stability despite very limited public disclosure. The company has operated for over 20 years since its founding in 2001, surviving multiple hosting-market cycles including the dot-com aftermath and cloud commoditisation. It is self-financed and owner-managed, implying a conservative capital structure with no debt-funded expansion. Its blue-chip institutional client base (Fresenius, WHO, Bertelsmann Stiftung, university hospitals, Suzuki, Melitta) typically generates predictable recurring revenue through managed-services contracts. However, the company's very small scale (~EUR 1.4M revenue) severely limits its buffer against major R&D investment, security incidents, or client attrition — a single large client loss would be material. It faces continuous margin pressure from hyperscalers (AWS, Azure, GCP, Hetzner, IONOS), key-person dependency on its two founding managing directors, and colocation concentration risk through its Interxion (Digital Realty) dependency. Public transparency is low as a small KG with no P&L disclosed, and its footprint is regionally concentrated in DACH with limited international diversification. Overall, the profile suggests a stable but small niche operator with resilience dependent on client retention and pricing power.
Key strengths: Over 20 years of operating history since 2001, Self-financed and owner-managed capital structure, Blue-chip client base including Fresenius, WHO, Bertelsmann Stiftung, Niche 'Hosting-Manufaktur' positioning with higher-margin bespoke services, Green-hosting certification providing ESG advantage, Recurring managed-services revenue model
Risk factors: Very small scale (~EUR 1.4M revenue) limits buffer for shocks, Hyperscaler competition pressuring margins, Key-person dependence on two founding managing directors, Data-center dependency on Interxion/Digital Realty, Low public financial transparency as small KG, Regional concentration in DACH with limited international diversification, Client concentration risk — loss of single large client would be material
Revenue by geography
- DACH (Germany/Austria/Switzerland): 90%
- International: 10%
Revenue by product/service
- Managed Hosting and Server Management: 75%
- Datacenter/Colocation Services: 25%
Workforce by country
- Germany: 12
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.