Mikrotikls SIA

Latvia · owned by Independent (Latvia) · mikrotik.com · 7 vendors

MikroTik (Mikrotikls SIA) is a Latvian company that designs and manufactures networking hardware and software, including routers, switches, wireless systems, and LTE/5G products used in nearly all countries of the world. The company develops RouterOS, a powerful network operating system that powers its RouterBOARD hardware line, as well as software tools such as WinBox and mobile apps. MikroTik serves a wide range of customers from home users to ISPs and enterprise networks, offering affordable yet high-performance networking solutions globally.

Resilience scores

Disruption prediction

Mikrotikls SIA has an estimated 27% probability of disruption in the next 6 months.

2 of Mikrotikls SIA's 7 vendors monitored for disruptions.

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 7 sub-vendors.

Insights

Last updated 2026-08-14 · revision 2

7 direct vendors, 71 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Mikrotikls SIA benefits significantly from its reported "Total Vendors: 0" for IT services, which means there is no vendor lock-in to external providers. This provides immense flexibility and control over any migration strategy, eliminating the complexities of contract renegotiations or proprietary system disentanglement. The existing presence of "Amazon AWS" in their internal tech stack suggests some familiarity with cloud environments, which can ease the transition for certain workloads. The absence of specified data residency requirements could also offer flexibility in choosing migration targets. The primary challenge for migration readiness lies in the fundamental nature of Mikrotikls' products and core technology. Their business revolves around hardware (routers, switches, RouterBOARD) and a deeply embedded operating system (RouterOS), developed in C/C++ on Unix/Linux. Migrating such a tightly integrated, low-level, and hardware-dependent stack to a fully cloud-native, containerized, or microservices architecture would require extensive re-architecture, significant investment, and potentially a complete redesign of core components. This makes a full "lift and shift" or rapid cloud adoption difficult. The "NIS2 Compliance: Assessment Required" also introduces potential regulatory complexities that would need to be carefully managed during any migration, especially concerning data and service locations. The lack of financial stability data prevents an assessment of the company's capacity to fund a potentially large-scale migration effort. Overall, while the absence of vendor lock-in is a major advantage, the deeply embedded and hardware-centric nature of their core products presents substantial technical hurdles for a comprehensive cloud migration, suggesting that a hybrid or selective migration approach would be more feasible than a full transformation.

Compliance

8 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 is an internationally recognized standard for Information Security Management Systems (ISMS). For a technology company of MikroTik's scale and global reach — producing networking hardware and software used in critical infrastructure worldwide, with 800+ distributors in 130 countries — ISO 27001 certification would be highly relevant and expected by enterprise and government customers. The company's active security vulnerability disclosure program and CVE management demonstrate security awareness, but no ISO 27001 certification has been found publicly. The absence of ISO 27001 certification creates commercial risk, particularly for government and enterprise procurement. Risk is Medium because: (1) MikroTik's products are used in critical infrastructure globally, (2) enterprise/government customers increasingly require ISO 27001 from vendors, (3) no certification evidence found, but (4) the company explicitly states '100% compliance with EU laws and regulations' on its company page, suggesting awareness of compliance obligations.

Evidence: https://mikrotik.com/aboutus/company, https://mikrotik.com/supportsec

Cyber Resilience Act (source) — Assessment Required

The EU Cyber Resilience Act (CRA), adopted in October 2024 and entering into force in stages through 2027, is directly and critically applicable to Mikrotikls SIA. The CRA imposes mandatory cybersecurity requirements on manufacturers and suppliers of products with digital elements (hardware and software) sold in the EU market. MikroTik is precisely the type of company the CRA targets: a manufacturer of networking hardware (routers, switches, wireless systems, IoT devices) and software (RouterOS) with digital elements. Key CRA obligations include: security-by-design requirements, vulnerability handling and disclosure obligations, mandatory security updates for the product lifecycle, CE marking for cybersecurity compliance, conformity assessments, and incident reporting to ENISA. Risk is High because: (1) CRA is directly applicable to MikroTik's core business; (2) non-compliance could result in market access restrictions (products cannot be sold in EU); (3) fines up to €15M or 2.5% of global annual turnover; (4) the CRA's reporting obligations for actively exploited vulnerabilities align with but expand upon MikroTik's existing CVE disclosure program; (5) MikroTik has had multiple significant CVEs in 2024-2025 affecting RouterOS, indicating ongoing vulnerability management needs.

Evidence: https://mikrotik.com/supportsec, https://mikrotik.com/aboutus/company, https://mikrotik.com/software

SOC 2 (source) — Assessment Required

SOC 2 is a voluntary framework developed by the AICPA applicable to service organizations that store, process, or transmit customer data in the cloud. Mikrotikls SIA provides cloud-connected services including the 'Back to Home' VPN app, eSIM connectivity services, RouterOS cloud features, mobile apps, and an online customer account portal. These services involve processing customer data in cloud environments, which is the core trigger for SOC 2 relevance. While SOC 2 is not legally mandated, enterprise and ISP customers — particularly in North America — increasingly require SOC 2 Type II reports from technology vendors as part of their vendor due diligence. The absence of a publicly available SOC 2 report may create commercial risk with enterprise customers. Risk is Medium because: (1) MikroTik does provide cloud-connected services, (2) enterprise customers may require SOC 2 attestation, (3) no SOC 2 report has been found publicly, but (4) SOC 2 is voluntary and MikroTik's primary business is hardware manufacturing rather than cloud SaaS.

Evidence: https://mikrotik.com/bth, https://mikrotik.com/connectivity, https://mikrotik.com/supportsec

Financials

Three-year financials

Financial Resilience Score: 9/10

Mikrotikls SIA demonstrates exceptional financial resilience for a private hardware manufacturer. The company has achieved 20%+ CAGR over the past decade with net margins consistently in the 25-35% range, which is remarkable for networking hardware. Growth has been entirely self-financed through retained earnings, with minimal external debt, indicating a very strong balance sheet and low financial leverage risk. The company's vertically integrated model—owning its RouterOS software and hardware design—creates high switching costs and gross margin protection versus commoditized competitors. Distribution through 800+ resellers across 130 countries provides significant geographic diversification and reduces customer concentration risk. The product portfolio spans from sub-€50 home routers to 400G data-center switches, insulating the business from single-segment downturns. The 2023 revenue decline of ~15% following the record 2022 demonstrates exposure to ISP capex cycles and channel inventory normalization, but profitability remained very strong. Key risks include semiconductor supply dependence, reputational exposure from security advisories (VPNFilter, Mēris botnet), competition from TP-Link/Ubiquiti/Huawei, and concentrated private ownership with limited governance disclosure.

Key strengths: Exceptional profitability with 25-35% net margins, Self-financed growth with minimal external debt, Global distribution across 800+ resellers in 130 countries, Sticky RouterOS software ecosystem with high switching costs, Broad product portfolio from consumer to data-center segments, Vertical integration (own OS and hardware design), 20%+ CAGR over past decade

Risk factors: Cyclicality of ISP/networking capex (evidenced by 2023 decline), Component/semiconductor supply dependency, Reputational risk from security advisories and botnet campaigns, Competition from TP-Link, Ubiquiti, Cisco Meraki, Huawei and Chinese ODMs, Key-person and private-ownership concentration risk, Currency risk (USD sales vs EUR costs)

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report