Mollie B.V.
Netherlands · www.mollie.com · 6 vendors
Resilience scores
- Digital Sovereignty: 17
- Digital Resilience: 8
- Financial Resilience: 7
Technology vendors
- Google LLC — Technology — United States
- Netlify, Inc. — Technology — United States
- Zendesk, Inc. — Technology — United States
- and 3 more
Services catalogue
2 services in catalogue across 2 categories; runs on 6 sub-vendors.
- Mollie
- Payments
Insights
Last updated 2026-08-12 · revision 2
6 direct vendors, 135 subvendors
Direct vendors by controlling owner country (sample)
- United States: 4
- Japan: 1
- Netherlands: 1
Subvendors by controlling owner country (sample)
- Canada: 1
- Sweden: 3
- Denmark: 3
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Mollie B.V. exhibits high migration readiness, largely due to its highly modern and cloud-native internal tech stack. The extensive use of Kubernetes, Docker, Microservices Architecture, and AWS positions the company for efficient and flexible migration strategies, whether re-platforming or re-hosting. This architecture allows for independent migration of components, reducing overall complexity and risk. The presence of well-defined REST APIs and various SDKs also facilitates integration during migration. Key challenges for migration readiness stem from the complex regulatory environment inherent to a financial institution operating across multiple European countries. Adherence to PCI-DSS, PSD2, 3D Secure, and EMI regulations means any migration must meticulously maintain compliance, requiring significant planning and potentially specialized expertise. The absence of specified data residency requirements is a notable unknown, as these are typically stringent for financial services and could introduce significant constraints. While the 'Total Vendors: 0' is ambiguous, the reliance on 6 external services from vendors across 3 countries implies dependencies that need careful management during a migration, potentially involving contract reviews or re-platforming of these services. The lack of financial stability data also prevents an assessment of the company's capacity to fund a large-scale migration effort.
Compliance
11 in-scope frameworks identified; showing 3.
GDPR (source) — Compliant
Mollie B.V. is headquartered in the Netherlands (EU) and processes large volumes of personal data as a licensed electronic money institution and payment service provider — including customer data, consumer payment data, UBO/identity data, and transactional data across 250,000+ businesses. GDPR is unambiguously applicable. Risk is rated Medium rather than Low because: (1) Mollie processes highly sensitive financial and identity data at scale, making any breach or non-compliance incident high-impact; (2) the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) is an active enforcer; (3) cross-border data transfers to third countries outside the EEA are acknowledged in their Privacy Statement, requiring ongoing SCCs management. However, Mollie demonstrates strong compliance posture: a formally appointed and registered DPO (registered with both the Dutch AP and UK ICO), a comprehensive published Privacy Statement explicitly referencing GDPR 2016/679 and UK GDPR, documented lawful bases, data subject rights procedures, and stated use of EU Standard Contractual Clauses for third-country transfers. Risk is not Low because the scale and sensitivity of data processed means any gap carries significant regulatory and reputational consequences.
Evidence: https://www.mollie.com/legal/privacy, https://www.mollie.com/security, https://www.mollie.com/legal/user-agreement/v10
SOC 2 (source) — Compliant
Mollie has publicly confirmed SOC 2 Type 2 certification on its official security page. SOC 2 Type 2 is the most rigorous form of SOC 2 assessment, covering a defined period of operational effectiveness (not just point-in-time design). This demonstrates that Mollie's security, availability, and confidentiality controls have been independently assessed against the AICPA's Trust Services Criteria and found effective. Risk is Low because the certification is confirmed, independently validated, and directly relevant to Mollie's role as a cloud-based payment platform processing sensitive financial data for 250,000+ businesses. The main residual risk is ensuring the certification remains current and covers all relevant systems.
Evidence: https://www.mollie.com/security
UK FCA Regulation — Compliant
Mollie UK Ltd is separately licensed and regulated by the UK Financial Conduct Authority (FCA) as a payment institution (FRN: 977968). This is confirmed by Mollie's own disclosures. FCA authorisation is a prerequisite for operating as a payment institution in the UK post-Brexit, and ongoing FCA supervision ensures continuous compliance monitoring. Risk is Low because the licensing is confirmed and FCA supervision is ongoing.
Evidence: https://www.mollie.com/, https://www.mollie.com/legal/privacy
Financials
Three-year financials
- 2024: revenue €214M
- 2023: revenue €99M
- 2022: revenue €73M
Financial Resilience Score: 7/10
Mollie demonstrates strong financial resilience following a significant operational turnaround. Revenue grew 36% in 2023 and 28-30% in 2024, while operating costs were cut approximately 30% from €179.8M in 2022 to €126.7M in 2023 and kept stable in 2024. This cost discipline enabled Mollie to achieve its first positive EBITDA since 2018, marking a major inflection point in the company's financial trajectory. The company is well-capitalised, having raised approximately USD 800M in its Series C round led by Blackstone Growth in 2021, on top of €25M Series A (2019) and €90M Series B (2020). Mollie's own 2023 disclosure describes a strong cash position. It holds regulatory licences from DNB (EMI) and the FCA (UK), providing solid access to European payment schemes. However, resilience is tempered by limited public disclosure (EBIT, net income, equity, and cash burn history are not fully public), intense competition from Adyen, Stripe, Worldline, PayPal, and Checkout.com, and execution risk from rapid multi-country expansion across 25+ EEA markets. The pending GoCardless acquisition represents the largest integration challenge in Mollie's history, and the private fintech valuation reset since 2022 could weigh on future capital raises.
Key strengths: Revenue growth of 36% (2023) and 28-30% (2024), First positive EBITDA since 2018 achieved in 2024, Operating costs cut ~30% from 2022 to 2023 (€179.8M to €126.7M), Well-capitalised with ~USD 800M Series C from Blackstone Growth (2021), DNB-licensed EMI and FCA-authorised UK subsidiary, Diversified pan-European footprint across 25+ EEA markets, ~250,000 SMB customers reducing single-customer concentration, Product expansion into higher-margin lines (Capital, Business Accounts, Connect)
Risk factors: Limited public disclosure of EBIT, net income, equity, and unit economics, Intense competition from Adyen, Stripe, Worldline/Nexi, PayPal, Checkout.com, Regulatory exposure to PSD2/PSD3, DORA, MiCA, AML/KYC intensification, Credit risk from scaling Mollie Capital SMB lending, FX and sovereign expansion risk across multiple new markets, Integration risk from pending GoCardless acquisition, Valuation reset risk versus 2021 Series C valuation of ~USD 6.5B, Definitional inconsistency between 2023 net revenue and 2024 revenue disclosures
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.