LoRa Alliance

United States · lora-alliance.org · 18 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 18 sub-vendors.

Insights

Last updated 2026-08-14 · revision 6

18 direct vendors, 218 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

The LoRa Alliance exhibits a medium level of migration readiness (Score: 65). A key advantage is that its current internal tech stack is predominantly composed of modern, cloud-based SaaS solutions (e.g., WordPress, HubSpot, GitHub, YouTube, Cvent). This implies that the organization is already operating in a distributed, service-oriented manner, reducing the complexity typically associated with migrating monolithic, on-premise legacy systems. However, several factors present challenges to high migration readiness. The regulatory environment requires 'Assessment' for GDPR, SOC2, and ISO 27001, each carrying a 'Medium' risk. Any significant migration would necessitate careful consideration of these compliance requirements, potentially increasing complexity, cost, and timelines, especially concerning data handling and security. Data residency requirements also indicate that while personal data is processed in the US, the global membership base means various data localization needs must be addressed, complicating cross-border data transfers during a migration. Furthermore, while the 'Total Vendors: 0' data is confusing, the reliance on specific SaaS platforms like HubSpot for CRM and Cvent for event management suggests a moderate level of vendor lock-in. Migrating away from these established platforms could involve substantial data extraction, transformation, and re-platforming efforts. The lack of detailed financial growth history also makes it difficult to assess the organization's capacity to fund a major migration initiative. Addressing compliance gaps and strategically evaluating vendor dependencies would enhance their migration readiness.

Compliance

8 in-scope frameworks identified; showing 3.

US Nonprofit — Assessment Required

LoRa Alliance is incorporated as a nonprofit association (Certificate of Incorporation publicly available on its website). Industry associations of this type typically qualify for IRS 501(c)(6) tax-exempt status (business leagues). Risk is Low because: (a) the Alliance has been operational since 2015 with no publicly disclosed IRS compliance issues; (b) nonprofit compliance requirements for a standards body are well-established; (c) the Alliance publishes its Bylaws, IPR Policy, and Certificate of Incorporation, indicating governance transparency. The primary risk would be if the Alliance's activities were deemed to primarily benefit specific members rather than the industry as a whole, but this is a low-probability scenario for an established standards body.

Evidence: https://lora-alliance.org/wp-content/uploads/2026/01/LoRa-Alliance-Bylaws_Approved_08.08.2024.pdf, https://lora-alliance.org/wp-content/uploads/2021/05/LA-certificate-of-Incorporation_0.pdf, https://lora-alliance.org/wp-content/uploads/2023/03/LoRa-Alliance-IPR-Policy-Final-Approved-by-Board-March-17-2023.pdf, https://lora-alliance.org/about-lora-alliance/

Cyber Resilience Act (source) — Assessment Required

The EU Cyber Resilience Act (Regulation 2024/2847), adopted in October 2024 with phased implementation through 2027, imposes cybersecurity requirements on products with digital elements placed on the EU market — including IoT devices. LoRaWAN-certified devices are directly within scope of the CRA as 'products with digital elements.' While LoRa Alliance as a standards body is not itself a manufacturer subject to CRA, its certification program and security specifications will significantly influence how member companies achieve CRA compliance. Risk is Medium because: (a) the Alliance's LoRaWAN security specifications (128-bit AES encryption, authentication mechanisms) are directly relevant to CRA essential requirements; (b) the Alliance's certification program may need to evolve to incorporate CRA compliance pathways; (c) the Alliance's regulatory activities page confirms it monitors cybersecurity regulatory developments; (d) failure to align LoRaWAN certification with CRA requirements could disadvantage EU member companies. The Alliance's Security Working Group is the primary vehicle for addressing this.

Evidence: https://lora-alliance.org/security/, https://lora-alliance.org/regulatory-activities/, https://lora-alliance.org/lorawan-certification/

ISO 27001 (source) — Assessment Required

ISO 27001 is broadly applicable to any organization that manages information assets and seeks to demonstrate information security best practices. LoRa Alliance manages: (1) member personal data and contact information; (2) proprietary technical specifications and working group documents; (3) certification infrastructure and LCTT software; (4) NetID and VendorID assignment records critical to global LoRaWAN network operations; (5) intellectual property including the LoRaWAN standard itself. Risk is Medium because: (a) the Alliance's certification and standards infrastructure is relied upon globally by hundreds of member companies; (b) a compromise of the NetID/VendorID system or certification tools could have significant ecosystem-wide impact; (c) no ISO 27001 certification has been publicly disclosed; (d) the privacy policy references basic security measures but not a formal ISMS. The nonprofit nature and relatively small staff size reduce the likelihood of a formal ISO 27001 certification being in place, but the criticality of the information assets managed warrants assessment. The Alliance's own Security Working Group and active engagement with cybersecurity regulatory frameworks suggest security awareness, but this does not confirm ISO 27001 certification.

Evidence: https://lora-alliance.org/about-lora-alliance/, https://lora-alliance.org/privacy-policy/, https://lora-alliance.org/wp-content/uploads/2023/03/LoRa-Alliance-IPR-Policy-Final-Approved-by-Board-March-17-2023.pdf

Financials

Three-year financials

Financial Resilience Score: 6/10

The LoRa Alliance is a non-profit industry standards consortium, not a for-profit enterprise, so traditional financial metrics like revenue, EBIT, and equity are not publicly disclosed. Its financial resilience must be assessed qualitatively. The organization benefits from a broad and diversified member base spanning geographies and industries, ranging from large corporations like Semtech, Cisco, and AWS to startups, universities, and government entities, which reduces dependence on any single funder. Its recurring revenue model from annual membership dues and certification fees provides a predictable base. The alliance operates with low capital intensity as a standards body, requiring mostly staff, events, and secretariat functions. Strong network effects from LoRaWAN's position as the leading open LPWAN standard with 600+ certified devices provide incumbency advantages. Backing by Semtech Corp., the primary silicon vendor of LoRa chips, gives strategic financial support. However, significant risks exist including competition from NB-IoT, LTE-M, Sigfox, and Mioty standards, concentration risk tied to Semtech's LoRa physical-layer IP ownership, membership churn risk during IoT market slowdowns, event revenue exposure to macro conditions, and complete lack of public financial transparency preventing independent assessment of reserves and liquidity.

Key strengths: Broad diversified member base across geographies and industries, Recurring revenue from annual membership dues and certification fees, Strong network effects with 600+ certified devices, Low capital intensity operating model, Strategic backing by Semtech Corp., LoRaWAN adopted as ITU-T Y.4480 international standard

Risk factors: Competitive pressure from NB-IoT and LTE-M cellular LPWAN standards, Concentration risk tied to Semtech's LoRa physical-layer IP ownership, Membership churn during IoT market slowdowns, No public financial transparency, Event revenue exposure to macro conditions and travel budgets, Competition from Sigfox (UnaBiz) and Mioty alternatives

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report