Miercom

United States · www.miercom.com · 8 vendors

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 8 sub-vendors.

Insights

Last updated 2026-08-02 · revision 1

8 direct vendors, 113 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Miercom demonstrates medium migration readiness, leaning towards the lower end due to its current technology stack. The primary challenge for migration is the internal tech stack, which is built on WordPress and Elementor. This traditional web platform is not inherently cloud-native, containerized, or microservices-based, meaning a significant migration to a modern cloud architecture would likely necessitate substantial re-platforming and development effort. The absence of data on financial stability makes it impossible to assess the company's capacity to fund a potentially large-scale migration project. While 'Total Vendors: 0' is noted as contradictory, assuming the 4 services from vendors in Bulgaria and the United States, there could be some level of vendor lock-in, the extent of which is unknown and could complicate migration. On the positive side, the lack of specified data residency requirements offers flexibility in choosing cloud regions during a migration. Similarly, the regulatory environment is not specified, so potential compliance hurdles are unknown, which could be either an advantage or a hidden challenge.

Compliance

5 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS). It is highly relevant to Miercom given that: (1) Miercom handles confidential and proprietary vendor product data, test results, and competitive intelligence during testing engagements; (2) Miercom's clients include major global technology vendors who routinely require ISO 27001 certification from their service providers as part of vendor risk management; (3) Miercom itself offers security testing and certification services, making its own security posture a reputational and commercial consideration. Risk is Medium because the absence of ISO 27001 certification could represent a competitive disadvantage and a supply chain security risk for Miercom's enterprise clients, though ISO 27001 is voluntary and non-compliance does not carry direct regulatory penalties. Missing information: whether Miercom holds an unpublished or in-progress ISO 27001 certification, and what internal ISMS controls are in place.

Evidence: https://miercom.com/about-us/, https://miercom.com/services/certifications/, https://www.iso.org/standard/27001, https://miercom.com/services/security-assured/

SOC 2 (source) — Assessment Required

SOC 2 (System and Organization Controls 2) is a voluntary framework developed by the AICPA applicable to service organizations that store, process, or transmit customer data in the cloud or via technology systems. Miercom provides testing, certification, and consulting services to technology vendors and enterprises. In the course of these engagements, Miercom likely receives and processes confidential vendor product data, test configurations, proprietary technical information, and potentially client contact/business data. Enterprise clients and large technology vendors increasingly require their service providers — including testing labs — to demonstrate SOC 2 compliance as part of vendor due diligence. Risk is Medium because: (1) Miercom handles confidential vendor data as part of its testing engagements; (2) No SOC 2 report or certification is publicly disclosed; (3) The absence of SOC 2 may be a barrier to enterprise client acquisition; (4) However, SOC 2 is voluntary and Miercom may have alternative contractual security assurances in place.

Evidence: https://miercom.com/services/testing/, https://miercom.com/services/certifications/, https://miercom.com/about-us/, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services

CPRA — Assessment Required

The CCPA/CPRA applies to for-profit businesses that collect personal information from California residents and meet one or more thresholds: (1) annual gross revenues exceeding $25 million; (2) annually buy, sell, or share personal information of 100,000+ consumers/households; or (3) derive 50%+ of annual revenues from selling/sharing personal information. Miercom is a US-based company that collects contact information via its website from visitors including California residents. Given Miercom's 30+ year history and global client base, it is plausible that revenue thresholds may be met, though exact revenue figures are not publicly available. Risk is Medium because: (1) Miercom's website collects personal data from California residents; (2) No privacy policy or CCPA-specific disclosures are publicly visible; (3) Revenue threshold applicability is uncertain without financial data.

Evidence: https://miercom.com/contact-us/, https://miercom.com/tou/, https://oag.ca.gov/privacy/ccpa

Financials

Three-year financials

Financial Resilience Score: 6/10

Miercom is a long-established, privately held US testing and certification firm founded in 1988, giving it roughly 37 years of operating history in a specialized niche. Its longevity, strong brand recognition in independent network and cybersecurity product testing, and blue-chip client roster (Cisco, Check Point, Palo Alto Networks, Fortinet, Juniper, HPE/Aruba, and 80+ named vendors) suggest stable cash generation and recurring revenue characteristics from annual Industry Assessments and repeat certification testing across product cycles. The business model is engineering-services based with low capital intensity, reducing the need for external financing. However, because Miercom is private and not subject to US public-company disclosure requirements, no verified revenue, EBIT, equity, or headcount figures are publicly available. This lack of transparency prevents external verification of solvency, leverage, or cash reserves. Key risks include potential vendor concentration (loss of one or two major sponsors could materially impact revenue), independence/perception risk inherent to vendor-sponsored testing labs, competition from Tolly Group, CyberRatings.org, AV-TEST, AV-Comparatives, ICSA Labs, and SE Labs, and cyclicality tied to vendor marketing budgets. A moderate resilience score reflects the strong qualitative franchise offset by opacity and small-firm structural risks.

Key strengths: Long operating history since 1988 (~37 years) in a stable niche, Strong brand in independent testing widely cited by major vendors, Diverse vendor base of 80+ named relationships reducing single-customer concentration, Recurring revenue from annual Industry Assessments and repeat certification testing, Low capital intensity engineering-services model with limited external financing needs

Risk factors: Small, private, undisclosed financials preventing external verification of solvency and leverage, Key-vendor concentration risk from potential loss of major sponsors like Cisco or Check Point, Perception/independence risk inherent to vendor-sponsored testing labs, Competition from Tolly Group, CyberRatings.org, AV-TEST, AV-Comparatives, ICSA Labs, SE Labs, Cyclicality tied to vendor marketing budgets that can decline in downturns

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report