Kyndryl
United States · www.kyndryl.com · 10 vendors
Kyndryl Holdings, Inc. is the world's largest IT infrastructure services provider, designing, building, managing, and modernizing complex, mission-critical information systems. The company serves thousands of enterprise customers in over 60 countries, offering services across cloud, security and resiliency, network and edge computing, digital workplace, core enterprise, and applications, data, and AI.
Resilience scores
- Digital Sovereignty: 90
- Digital Resilience: 6
- Financial Resilience: 4
Disruption prediction
Kyndryl has an estimated 11% probability of disruption in the next 6 months.
6 of Kyndryl's 10 vendors monitored for disruptions.
Technology vendors
- Adobe Inc. — Technology — United States
- Demandware — Technology — United States
- Tealium — Technology — United States
- and 16 more
Services catalogue
8 services in catalogue across 3 categories; runs on 10 sub-vendors.
- Bridge
- Hybrid cloud services
- IT infrastructure modernization
Insights
Last updated 2026-09-13 · revision 2
10 direct vendors, 152 subvendors
Direct vendors by controlling owner country (sample)
- United States: 9
- France: 1
Subvendors by controlling owner country (sample)
- Denmark: 2
- France: 3
- Sweden: 2
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Kyndryl's migration readiness is assessed as medium-high. The most significant positive factor is 'Total Vendors: 0', which, if accurate, indicates a complete absence of vendor lock-in. This is a critical enabler for any migration effort, as it removes a major source of complexity and cost associated with disentangling from vendor contracts and proprietary systems. However, this data point contradicts 'Total Services: 28' and the provided vendor geographic diversity information (4 unique countries for HQ/owner), which are also listed under 'Vendor Relationships'. If 'Total Vendors: 0' is strictly interpreted, then the other vendor-related data points are not applicable to Kyndryl's direct vendor lock-in. The assessment is limited by the lack of information on Kyndryl's internal tech stack (e.g., cloud-native, containerization, microservices adoption), specific regulatory environment, data residency requirements, and financial capacity to fund a large-scale migration. These unknowns prevent a higher readiness score.
Compliance
6 in-scope frameworks identified; showing 3.
GDPR (source) — Compliant
Kyndryl operates extensively in EU/EEA countries and processes personal data of EU residents through its global IT infrastructure services. While the company demonstrates awareness of GDPR through its privacy framework and data protection policies, the medium risk reflects the complexity of managing cross-border data flows and the significant financial penalties (up to 4% of global turnover) for non-compliance. As a large multinational with substantial EU operations, regulatory scrutiny is higher.
Evidence: https://www.kyndryl.com/us/en/about-us/trust, https://www.kyndryl.com/us/en/privacy/baseline, https://www.kyndryl.com/us/en/privacy/data-privacy-framework
ISAE 3000 (source) — Assessment Required
ISAE 3000 assurance services may be relevant for Kyndryl's service delivery and customer assurance requirements. Low risk reflects that this is typically a customer-driven requirement rather than a regulatory mandate. The impact of non-compliance would primarily affect specific customer relationships rather than pose broader regulatory or financial risks.
NIS2 (source) — Compliant
Kyndryl is classified as an 'essential entity' under NIS2 due to its digital infrastructure and ICT service management operations in the EU. The company has established dedicated compliance structures (Kyndryl Europe Regulatory Team) and technical controls. Medium risk reflects the strict incident reporting requirements (24-hour initial reporting) and potential operational disruptions from non-compliance, though the company appears well-prepared with robust CSIRT teams and governance frameworks.
Evidence: https://www.kyndryl.com/us/en/about-us/trust/nis2, https://www.kyndryl.com/us/en/about-us/trust
Financials
Three-year financials
- 2026: revenue USD 15.1B, equity USD 1.18B
- 2025: revenue USD 15.1B, equity USD 1.22B
- 2024: revenue USD 16.1B, equity USD 1.01B
Financial Resilience Score: 4/10
Kyndryl has faced persistent operating losses since its spin-off from IBM in November 2021, reflecting the significant restructuring challenges inherent in transitioning a legacy IT infrastructure services business into an independent, modernized entity. The company has reported negative EBIT across all reported fiscal years, though losses have been narrowing, suggesting the 'three-A' transformation strategy (Advancing, Alliances, Accounts) is beginning to yield operational improvements. Adjusted pretax income turned positive in FY2024, which is an encouraging sign of underlying progress beneath GAAP losses driven by restructuring and amortization charges. Revenue has been declining steadily as Kyndryl sheds low-margin legacy contracts and focuses on higher-value managed services and hybrid cloud infrastructure. While this strategic pruning is intentional, it compresses the top line and creates near-term financial pressure. The company carries a meaningful debt load inherited from the IBM spin-off, though it has been actively deleveraging. Liquidity appears adequate with access to credit facilities, but the thin equity base relative to total assets limits financial flexibility. Kyndryl benefits from a large, diversified global customer base including many Fortune 500 and government clients with long-term contracts, providing revenue visibility. Strategic alliances with Microsoft, AWS, Google Cloud, and others are expanding addressable markets and improving competitive positioning. However, the company operates in a highly competitive, commoditizing market segment where pricing pressure is intense and customer attrition from legacy contracts remains a headwind. Overall, Kyndryl's financial resilience is below average for a company of its scale. The path to sustained profitability is visible but execution risk remains high, and the balance sheet provides limited buffer against unexpected shocks. The improving trajectory of adjusted metrics and alliance momentum are the primary mitigating factors against a lower score.
Key strengths: Adjusted pretax income turned positive in FY2024, indicating underlying operational improvement, Large diversified global customer base with long-term managed services contracts providing revenue visibility, Strategic hyperscaler alliances (Microsoft, AWS, Google Cloud) expanding addressable market, Intentional shedding of low-margin legacy contracts improving margin profile over time, Active deleveraging reducing inherited IBM spin-off debt burden
Risk factors: Persistent GAAP operating losses across all post-spin-off fiscal years, Continued top-line revenue decline as legacy contracts roll off, Thin equity base relative to total assets limits financial flexibility, Highly competitive and commoditizing IT infrastructure services market, Significant restructuring and transformation execution risk, Customer attrition from legacy contract portfolio
Revenue by geography
- United States: 25%
- Other EMEA: 18%
- Japan: 15%
- Other Americas: 12%
- Other Asia Pacific: 12%
- United Kingdom: 10%
- Germany: 8%
Revenue by product/service
- Managed Services (Cloud, Network & Edge, Core Enterprise & zCloud, Applications, Data & AI, Security & Resiliency, Digital Workplace): 85%
- Consulting & Implementation: 10%
- Other: 5%
Workforce by country
- India: 90000
- Other: 42000
- United States: 25000
- Japan: 15000
- United Kingdom: 10000
- Germany: 8000
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.