Kontron
Germany · www.kontron.com · 16 vendors
Resilience scores
- Digital Sovereignty: 38
- Digital Resilience: 9
- Financial Resilience: 7
Technology vendors
- Cookiebot (Cybot A/S) — Technology — Denmark
- Demandware — Technology — United States
- Usercentrics GmbH — Technology — Germany
- and 13 more
Services catalogue
1 service in catalogue across 1 category; runs on 16 sub-vendors.
- Network Appliances
Insights
Last updated 2026-07-02 · revision 1
16 direct vendors, 225 subvendors
Direct vendors by controlling owner country (sample)
- Germany: 3
- Denmark: 1
- India: 1
Subvendors by controlling owner country (sample)
- France: 8
- China: 3
- Switzerland: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Kontron exhibits a medium-high level of migration readiness, primarily driven by its adoption of modern software development and deployment practices. The tech stack includes container isolation (Docker-compatible), CLI-based deployment pipelines, and OTA update infrastructure, which are strong enablers for migrating to cloud-native or hybrid environments. Their experience with hardened Linux OS (KontronOS) also suggests a mature approach to software lifecycle management. However, several factors present challenges to migration. Many of Kontron's products are deeply embedded systems, often with specific hardware dependencies (e.g., BIOS/UEFI, TPM), which can complicate migration to generic virtualized or cloud platforms. Furthermore, while compliance with CRA, NIS-2, and IEC 62443 is a resilience strength, it introduces significant complexity and cost to migration efforts, as new environments must also be rigorously validated against these stringent industrial and cybersecurity standards. The lack of data on financial stability and specific data residency requirements also introduces unknowns. While the vendor data suggests geographic diversity (8 unique countries for 16 services), the 'Vendor Lock-in Risk: Unknown' and the contradictory 'Total Vendors: 0' make a precise assessment of vendor lock-in difficult, though the diversity generally points to lower lock-in compared to a highly concentrated vendor base.
Compliance
9 in-scope frameworks identified; showing 3.
CSRD (source) — Assessment Required
Kontron AG is a large listed company on the Vienna Stock Exchange with revenues exceeding €1.4B and 6,000+ employees, making it subject to CSRD mandatory sustainability reporting. Risk is Medium because: (1) CSRD applies to large listed EU companies from financial year 2024 (reporting in 2025); (2) Kontron already publishes ESG reports and references sustainability on its website; (3) CSRD requires detailed reporting under European Sustainability Reporting Standards (ESRS) covering environmental, social, and governance topics; (4) non-compliance risks regulatory sanctions and reputational damage; (5) Kontron's ESG ratings (Sustainalytics 20.2 points, MSCI confirmed per 2023 news) demonstrate existing ESG reporting maturity.
Evidence: https://www.kontron.com/en/group/esg, https://www.kontron.com/en/group/about-us, https://www.kontron.com/en/media/news/esg-kontrons-increased-transparency-rewarded-by-esg-rating-agencies?eqs=2592079, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2464
NIS2 (source) — Assessment Required
Kontron AG is highly likely to be subject to NIS2 as both a direct obligated entity and as a supplier to critical infrastructure operators. Multiple NIS2 applicability vectors exist: (1) Kontron Transportation provides mission-critical railway communication systems (GSM-R, FRMCS) — transport is an Essential Entity sector under NIS2 Annex I; (2) Kontron supplies energy management and smart grid solutions — energy is an Essential Entity sector; (3) Kontron provides digital infrastructure and ICT services including 5G modules, edge computing, and cybersecurity solutions — digital infrastructure/ICT service management are Essential Entity sectors; (4) Kontron's electronics manufacturing (KATEK subsidiary) falls under manufacturing of critical products (Important Entity); (5) Kontron explicitly markets NIS2-compliant solutions and references 'future-proof security solutions ensuring NIS2 compliance' on its About Us page. The company far exceeds the size thresholds (€1.4B+ revenue, 6,000+ employees). Risk is High because non-compliance with NIS2 can result in fines up to €10M or 2% of global turnover, mandatory incident reporting obligations, and management liability. Austria transposed NIS2 via the NISG 2024 (Netz- und Informationssystemsicherheitsgesetz).
Evidence: https://www.kontron.com/en/group/about-us, https://www.kontron.com/en/landing-pages/cyber-resilience-act-solutions-for-embedded-and-edge-systems, https://www.kontron.com/en/media/news/kontron-secures-eur-20-million-cybersecurity-contract?eqs=709663911, https://www.kontron.com/en/media/news/technology-update-kontrons-secureos-solution-offers-data-protection-for-critical-infrastructure, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555
GDPR (source) — Assessment Required
Kontron AG is headquartered in Linz, Austria — an EU member state — making GDPR universally applicable. As a large multinational technology group with ~6,000+ employees across Europe and globally, Kontron processes substantial volumes of personal data including employee records, customer data, supplier data, and potentially end-user data through its IoT platforms and SuSiEtec toolset. The company's IoT and edge computing products may also process personal data on behalf of customers (acting as a data processor), creating additional GDPR obligations. The risk level is High due to: (1) the scale and complexity of data processing across multiple jurisdictions; (2) IoT/connected device products that may process personal data; (3) cross-border data transfers to the US (San Diego operations, BSQUARE subsidiary) and Canada requiring appropriate transfer mechanisms; (4) GDPR fines can reach €20M or 4% of global annual turnover (~€56M+ based on 2025 revenues); (5) Austrian and German DPAs are active enforcement authorities. No public GDPR audit reports or DPO appointment disclosures were found on the company website.
Evidence: https://www.kontron.com/en/group/about-us, https://www.kontron.com/en/, https://gdpr-info.eu/, https://www.dsb.gv.at/
Financials
Three-year financials
- 2025: revenue EUR 1.61B
- 2024: revenue EUR 1.68B
- 2023: revenue EUR 1.23B
Financial Resilience Score: 7/10
Kontron AG exhibits solid financial resilience characterized by strong revenue scale (EUR 1.6B+), consistently improving margins (gross margin rising from 38.0% in 2023 to 42.1% in 2025; EBITDA margin reaching ~13.7% adjusted in 2025), and a robust order backlog of approximately EUR 2.5 billion at end-2025, representing roughly 1.5 years of revenue visibility. The book-to-bill ratio has remained above 1.2 for three consecutive years, indicating sustained demand momentum. Cash generation is strong with record operating cash flow of EUR 167.7M in 2025, net debt declining to EUR 147.1M, and equity ratio improving from 35.8% to 41.8%. An additional EUR 126M cash inflow is expected from the congatec deal by Q3 2026. However, resilience is tempered by portfolio churn (repeated divestments including IT services in 2022, TeleAlarm in 2024, and JUMPtec/COM in 2025) making comparability difficult, plus struggles in the GreenTec/solar business (revenue declining from EUR 193M to EUR 151M in 2025, with a ~EUR 25M restructuring cost planned for 2026 involving ~500 job cuts). Concentration in lumpy defense and rail project business, geopolitical/tariff exposure, and the pending Ennoconn mandatory takeover offer introduce further uncertainty. Historical Viceroy short-seller allegations, though closed by Deloitte forensic investigation, remain a reputational overhang.
Key strengths: Order backlog of EUR 2.5B providing ~1.5 years revenue visibility, Book-to-bill ratio consistently above 1.2, Rising gross margins (38.0% → 42.1%) and EBITDA margins, Record operating cash flow of EUR 167.7M in 2025, Equity ratio improved to 41.8% from 35.8%, Net debt declining to EUR 147.1M, Strategic backing from Ennoconn (Foxconn group), Structural tailwinds from EU Cyber Resilience Act, defense spending, 5G/AI edge computing
Risk factors: GreenTec/solar business under stress with declining revenue and EBIT losses, EUR 25M restructuring cost in 2026 with ~500 job cuts, Repeated portfolio divestments make year-on-year comparisons difficult, Concentration in lumpy defense/rail project business, Geopolitical and US tariff exposure, M&A leverage and purchase-price allocation amortization drag, Pending Ennoconn mandatory takeover offer creates corporate-action uncertainty, Historical Viceroy Research short-seller allegations reputational overhang
Revenue by geography
- Europe and Rest of World: 85%
- US and China: 15%
Revenue by product/service
- Hardware / Electronics² (EMS/ODM): 54%
- Software + Solutions: 37%
- GreenTec (solar + eMobility): 9%
Workforce by country
- Total (Global): 7000
- Engineers (Global): 3600
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.