Mittwald CM Service GmbH & Co. KG

Germany · www.mittwald.de · 18 vendors

Mittwald is a German web hosting company that provides high-performance managed hosting solutions for agencies and freelancers. The company operates its own ISO 27001-certified, climate-neutral data center in Germany. They offer various hosting packages, including web hosting, vServer, and dedicated servers.

Resilience scores

Disruption prediction

Mittwald CM Service GmbH & Co. KG has an estimated 27% probability of disruption in the next 6 months.

7 of Mittwald CM Service GmbH & Co. KG's 18 vendors monitored for disruptions.

Technology vendors

Services catalogue

6 services in catalogue across 3 categories; runs on 18 sub-vendors.

Insights

Last updated 2026-08-19 · revision 1

18 direct vendors, 169 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 3/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Mittwald's migration readiness is assessed as low (25/100) primarily due to a significant lack of information across all critical assessment areas. There is no data available on the company's internal tech stack, such as the adoption of cloud-native technologies, containerization, or microservices, which are key indicators of technical readiness for migration. The regulatory environment is not specified, making it impossible to anticipate potential compliance challenges or requirements during a migration. Similarly, data residency requirements are "Not specified," introducing an unknown variable that could significantly impact migration strategy and complexity. Financial stability data (revenue concentration, growth history) is also absent, preventing an assessment of the company's capacity to fund a substantial migration project. Vendor lock-in risk is explicitly stated as "Unknown." While vendor geographic diversity is present, the actual number of vendors and the complexity of contracts for the "Total Services: 26" are not provided, making it difficult to gauge the ease of transitioning services or mitigating vendor dependencies. The contradictory "Total Vendors: 0" with detailed vendor country information further complicates the assessment of vendor relationships for migration readiness. Without clear insights into these fundamental aspects, the company's ability to undertake a smooth and efficient migration is highly uncertain, warranting a low readiness score.

Compliance

9 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Compliant

Mittwald explicitly and publicly claims ISO 27001 certification, certified by TÜV Rheinland — one of Germany's most reputable and internationally recognized certification bodies. This certification is prominently displayed on their technology page and homepage, and is used as a key marketing differentiator. ISO 27001 certification requires successful completion of a formal audit by an accredited certification body, followed by annual surveillance audits and triennial recertification. The risk level is Low because: (1) certification is confirmed by a reputable third-party body (TÜV Rheinland); (2) it is actively maintained and marketed; (3) the company's own data center operations are the scope of certification; (4) 24/7 monitoring, AI-based anomaly detection, and redundant systems are documented. The main residual risk is that the exact scope and current validity of the certificate cannot be independently verified without access to the TÜV Rheinland certificate registry.

Evidence: https://www.mittwald.de/darum-mittwald/technologie, https://www.mittwald.de/

SOC 2 (source) — Assessment Required

SOC 2 is a US-origin voluntary framework (AICPA) primarily relevant for cloud service providers and SaaS companies serving US enterprise customers. Mittwald is a German hosting provider primarily serving German/EU-based agencies and freelancers. SOC 2 is not legally mandated in Germany or the EU. While Mittwald operates cloud-like hosting services (vServer, container hosting, AI hosting), their primary market is German-speaking agencies, and their compliance posture is built around ISO 27001 (TÜV Rheinland certified) rather than SOC 2. No SOC 2 report or attestation has been found. The risk of non-compliance is Low because SOC 2 is not legally required in their jurisdiction and their customer base does not appear to demand it as a contractual requirement. If they expand to serve US enterprise clients, SOC 2 demand may increase.

Evidence: https://www.mittwald.de/darum-mittwald/technologie

GoBD — Compliant

GoBD is a German tax authority (BMF) guideline governing the proper keeping and retention of electronic books, records, and documents. It is applicable to all German businesses for their own accounting records. Additionally, Mittwald explicitly offers GoBD-compliant email archiving as a product feature ('GoBD-konforme E-Mail-Archivierung'), demonstrating active compliance with and commercial exploitation of GoBD requirements. Risk is Low because: (1) Mittwald actively markets GoBD compliance as a product feature; (2) as a German company they are subject to GoBD for their own records; (3) the product offering demonstrates deep familiarity with the standard.

Evidence: https://www.mittwald.de/produkte/webmail-archiv, https://www.mittwald.de/

Financials

Three-year financials

Financial Resilience Score: 7/10

Mittwald CM Service GmbH & Co. KG appears financially resilient by structure, though exact figures are not publicly disclosed due to HGB size-related disclosure relief. The company has a 20+ year track record of continuous organic growth since 2003 without any known distress event, and has funded significant capex (own data centre in 2011, second office building in 2017) from retained earnings, strongly suggesting sustained profitability. The recurring-revenue managed hosting model provides highly predictable subscription-like MRR/ARR with historically strong gross margins in the German hosting sector. The business is owner-operated by founder Robert Meyer, which typically implies conservative balance-sheet management and low debt tolerance. A sticky agency customer base (over 4,000 agency customers as of 2020) and the mStudio platform increase switching costs. Steady headcount growth (100 in 2011 → 150 in 2020 → 200 in 2025, ~5% CAGR) reflects a mature, profitable niche-hosting SME. Key risks include intense competition from larger hosters (IONOS, Hetzner, Strato) and hyperscalers (AWS, Azure, GCP), single-site concentration risk at the Espelkamp data centre, key-person/succession risk around the founder, and capex intensity from ongoing AI/GPU and data centre investment. Limited financial transparency may also complicate large enterprise procurement.

Key strengths: 20+ year track record of continuous organic growth since 2003, Recurring subscription-based revenue model with predictable MRR/ARR, Owner-financed capex (own data centre, second building) suggests sustained profitability, Owner-operated family business with conservative balance-sheet management, Sticky agency customer base with 4,000+ agency customers (2020), Own ISO 27001 certified data centre with renewable energy, Product diversification into mStudio, container and AI hosting

Risk factors: Intense competition from larger German/EU hosters and global hyperscalers, Scale disadvantage vs hyperscalers in AI/container hosting, Single-site concentration risk at Espelkamp data centre, Key-person/succession risk around founder Robert Meyer, Limited financial transparency due to HGB size-relief filings, Capex intensity from data centre expansion, GPU hardware and cybersecurity, Addressable market limited to DACH region

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report