Kriesi
Austria · kriesi.at · 16 vendors
Kriesi.at, founded by Christian Budschedl, specializes in developing premium and user-friendly WordPress themes. The company's core business is WordPress theme development, complemented by top-notch customer support.
Resilience scores
- Digital Sovereignty: 31
- Digital Resilience: 5
Technology vendors
- Cookiebot (Cybot A/S) — Technology — Denmark
- Stripe, Inc. — Financial Services — United States
- Usercentrics GmbH — Technology — Germany
- and 13 more
Services catalogue
1 service in catalogue across 1 category; runs on 16 sub-vendors.
- WordPress Theme
Insights
Last updated 2026-03-12 · revision 2
16 direct vendors, 165 subvendors
Direct vendors by controlling owner country (sample)
- Cyprus: 1
- Australia: 1
- Denmark: 1
Subvendors by controlling owner country (sample)
- France: 4
- Poland: 1
- Netherlands: 2
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Kriesi's migration readiness is assessed as low-medium. A significant challenge for any potential migration is its reliance on a traditional WordPress and PHP tech stack, which is not inherently cloud-native, containerized, or microservices-oriented. This suggests a potentially monolithic architecture that would require substantial re-architecting and refactoring to move to modern cloud platforms. Furthermore, the proprietary "Avia Layout Builder" is a major source of internal vendor lock-in. This custom drag-and-drop page builder is deeply integrated into their flagship Enfold theme, making it difficult to migrate content and functionality to a different platform or theme without significant redevelopment effort and potential loss of existing design. The financial stability required to fund a large-scale migration is unknown due to missing data on revenue concentration and growth history. Similarly, regulatory environment and data residency requirements are not specified, which could introduce complex compliance hurdles and costs during a migration. While there is vendor geographic diversity for its 21 services, the total number of distinct vendors and the specific lock-in risks associated with these external relationships remain unknown. This lack of clarity, combined with the internal proprietary technology, indicates a challenging migration path.
Compliance
3 in-scope frameworks identified; showing 3.
GDPR (source) — Assessment Required
GDPR applies with HIGH certainty as Kriesi is an Austrian company (EU member state) that processes personal data including customer information, support forum data, newsletter subscriptions, and website analytics. Non-compliance carries severe penalties up to 4% of annual turnover or €20M. The company shows GDPR awareness with a comprehensive privacy policy, but compliance status requires detailed assessment of technical and organizational measures.
Evidence: https://kriesi.at/privacy-policy, https://kriesi.at/legal-information
SOC 2 (source) — Assessment Required
SOC2 is relevant as Kriesi provides digital services including customer support systems, user account management, and processes customer data. While not mandatory, SOC2 compliance would demonstrate security controls to customers and could be a competitive advantage. Risk is medium as it's voluntary but increasingly expected by business customers for service providers handling their data.
ISO 27001 (source) — Assessment Required
ISO 27001 is relevant for information security management as Kriesi handles customer data, payment information, and operates digital services. While not mandatory, it would demonstrate systematic approach to information security. Risk is medium as it's voluntary but increasingly important for customer trust and business credibility in digital services sector.
Financials
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.