Jeppesen
United States · ww1.jeppesen.com · 8 vendors
Resilience scores
- Digital Sovereignty: 88
- Digital Resilience: 8
- Financial Resilience: 7
Technology vendors
- Adobe Inc. — Technology — United States
- Demandware — Technology — United States
- Looker — Technology — United States
- and 13 more
Services catalogue
3 services in catalogue across 1 category; runs on 8 sub-vendors.
- Charts
- Flight Planning Solutions
- Navigation Data
Insights
Last updated 2026-08-19 · revision 3
8 direct vendors, 131 subvendors
Direct vendors by controlling owner country (sample)
- United States: 7
- Denmark: 1
Subvendors by controlling owner country (sample)
- Germany: 4
- United Kingdom: 6
- Belgium: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Jeppesen exhibits a medium-high level of migration readiness, primarily driven by its highly modern and cloud-native oriented tech stack. The use of AWS, Microsoft Azure, Kubernetes, Docker, Microservices Architecture, REST APIs, and CI/CD Pipelines indicates a strong foundation for agile development and cloud migration. The adoption of both AWS and Azure suggests a multi-cloud strategy, which reduces vendor lock-in to a single cloud provider and enhances portability. Financially, the company's $1.05B revenue in 2025 provides significant capacity to fund complex migration initiatives. However, migration readiness is significantly challenged by a highly complex and stringent regulatory environment. Regulations such as GDPR, NIS2, ITAR/EAR, FAA, EASA, and RTCA DO-200B/EUROCAE ED-76B impose strict requirements on data handling, security, and operational integrity. Data residency requirements are a notable constraint, with primary processing in the US, reliance on the DPF for EU/UK/Swiss data transfers, and potential US-only processing for military/government data. Any migration would need to meticulously ensure compliance with these diverse and often conflicting requirements, impacting cloud region choices and architectural decisions. The presence of Oracle Database, if on-premise and deeply integrated, could also pose a specific migration challenge. While vendor geographic diversity is present, the unknown level of vendor lock-in for the 20 services, particularly specialized aviation solutions, could introduce complexities and dependencies during a migration. The 2025 acquisition by Thoma Bravo may also introduce new strategic directives or requirements that could influence migration priorities and scope.
Compliance
11 in-scope frameworks identified; showing 3.
ISAE 3000 (source) — Assessment Required
ISAE 3000 is relevant for companies that provide assurance reports to third parties about their controls, processes, or non-financial information. For Jeppesen, ISAE 3000 could be applicable in the context of: (1) ISAE 3402 (equivalent to SOC 1) reports on controls at service organizations relevant to financial reporting for airline customers; (2) Sustainability/ESG assurance reporting. Given Jeppesen's role as a service organization processing data on behalf of airlines (which are publicly listed companies with financial reporting obligations), ISAE 3402 reports may be relevant. However, this is less certain than SOC 2. Risk is Low because ISAE 3000/3402 is less commonly required than SOC 2 in the aviation technology sector, and there is no public evidence of ISAE 3000 reporting by Jeppesen.
Evidence: https://trust.jepp.com, https://ww2.jeppesen.com/legal/
EASA Regulations — Compliant
EASA regulatory compliance is equally critical for Jeppesen's European operations. Jeppesen serves European commercial airlines, provides NavData for EASA-certified aircraft, and offers crew management solutions that must comply with EASA Flight Time Limitations (FTL) regulations (EU-OPS/ORO.FTL). Non-compliance with EASA requirements would prevent Jeppesen from serving the European aviation market, which represents a significant portion of its global business. The Frankfurt office (established 1957) serves as the European hub. Risk is High due to the safety-critical nature of aviation data and the regulatory consequences of non-compliance.
Evidence: https://ww2.jeppesen.com/about-us/, https://ww2.jeppesen.com/airline-crew-optimization-solutions/fatigue-risk-management/, https://ww2.jeppesen.com/navigation-solutions/navdata/, https://ww2.jeppesen.com/data-certifications-and-letters-of-acceptance/
CPRA — Compliant
Jeppesen ForeFlight is headquartered in Englewood, Colorado, and explicitly addresses California privacy rights in its Privacy Policy with a dedicated 'Privacy Notice for California Residents' section. The company confirms it does not sell personal information, honors Global Privacy Control (GPC) signals, and provides all required CCPA/CPRA rights (access, deletion, correction, portability, opt-out of sharing). Risk is Low because the company has demonstrated active CCPA/CPRA compliance with detailed disclosures, and the Global Privacy Office at +1-303-799-9090 handles California privacy rights requests.
Evidence: https://www.jeppesenforeflight.com/legal/privacy-policy
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
Jeppesen is a market-leading aviation software and data business with an estimated ~$1.0-1.1 billion in annual revenue and strong operating margins (reportedly ~30% EBITDA range), reflecting its dominant position in aeronautical charting, NavData, and airline optimization software. Its subscription-based recurring revenue model, high customer retention, and diversification across commercial, business, general, and military aviation segments provide meaningful stability. The company's 90+ year brand, regulatory certifications (FAA, EASA), and effective status as the de facto global standard in charting further underpin resilience. However, the 2025 carve-out from Boeing and acquisition by Thoma Bravo (as part of a ~$10.55B Digital Aviation Solutions deal) introduces execution risk, potential increased leverage typical of PE ownership, and loss of Boeing's implicit backing. Cyclical exposure to airline health and flight hours (as demonstrated during COVID-19), rising competition from Lido/NavBlue (Airbus), Garmin, and startups, and data-integrity/safety risks temper the score. Overall, the business fundamentals are strong but standalone financial transparency is limited and post-carve-out risks are elevated.
Key strengths: Dominant market position in aviation charting and NavData (de facto global standard), Recurring subscription revenue model with high customer stickiness, Diversification across commercial, business, general, and military aviation, 90+ year brand with FAA/EASA regulatory certifications, High software/data-driven margins (~30% EBITDA range reported), New owner Thoma Bravo has deep vertical software expertise
Risk factors: Post-carve-out execution risk separating IT/data/contracts from Boeing, Cyclical exposure to airline health and flight hours (COVID-19 precedent), Private equity ownership likely brings higher leverage and interest burden, Intensifying competition from Lido/NavBlue (Airbus), Garmin, SmartSky, and startups, Loss of Boeing's implicit backing may cause customer vendor-risk reassessment, Data-integrity and safety risk—single major error carries reputational consequences
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.