MoonPay

United States · www.moonpay.com · 29 vendors

MoonPay is a financial technology company that provides payment infrastructure for cryptocurrency and non-fungible tokens (NFTs). It enables individuals and businesses to buy, sell, and swap cryptocurrencies and digital assets using traditional payment methods such as credit cards, bank transfers, Apple Pay, and Google Pay. The company aims to simplify access to the blockchain-based financial ecosystem for its users.

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 1 category; runs on 29 sub-vendors.

Insights

Last updated 2026-07-05 · revision 1

29 direct vendors, 276 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

MoonPay exhibits a good level of migration readiness, largely due to its modern and API-driven internal tech stack. The use of TypeScript, React, Node.js, REST APIs, and a multi-cloud deployment architecture indicates a cloud-native or cloud-ready approach, facilitating potential migrations. The presence of a Developer Platform & API, along with a Headless Commerce Architecture, suggests modularity and an API-first design, which are crucial for flexible re-platforming or cloud migrations. Existing compliance frameworks (SOC 2 Type 2, PCI DSS 4.0.1, ISO 27001) imply well-defined processes and controls that can streamline a structured migration effort. However, several critical unknowns temper the overall readiness score. Data residency requirements are not specified, which is a key factor in determining where data can be moved and stored during a migration. The regulatory environment is also not detailed, and compliance requirements can significantly impact migration complexity and cost. Furthermore, financial stability data (revenue concentration, growth history) is missing, making it difficult to assess the company's capacity to fund a substantial migration. The vendor lock-in risk is explicitly stated as 'Unknown', and the conflicting data point of 'Total Vendors: 0' versus 'Total Services: 32' makes it challenging to accurately assess vendor concentration and potential lock-in, which could pose significant hurdles during a migration. While vendor geographic diversity across 5 countries is a positive, the lack of clarity on the number of vendors and specific contract complexities prevents a higher readiness assessment.

Compliance

15 in-scope frameworks identified; showing 3.

SOC 2 (source) — Compliant

MoonPay has publicly confirmed SOC 2 certification, with the SOC 2 badge prominently displayed on its security page. As a cloud-based financial services platform processing sensitive customer data for 35M+ accounts and serving ~500 business partners, SOC 2 is both applicable and actively maintained. Risk is Low because the certification is confirmed and publicly disclosed, demonstrating active compliance with Trust Service Criteria (Security, Availability, Confidentiality). The certification also supports MoonPay's B2B enterprise sales to partner companies requiring vendor security assurance.

Evidence: https://www.moonpay.com/security, https://security.moonpay.com, https://www.moonpay.com/about-us

AML — Compliant

AML/CFT compliance is the single highest-risk regulatory area for MoonPay given: (1) cryptocurrency businesses are the primary target of global AML enforcement actions; (2) MoonPay operates in 180 countries with 35M+ verified accounts requiring KYC/AML screening; (3) MoonPay is registered with FinCEN (US), FINTRAC (Canada), AUSTRAC (Australia), FCA (UK), and AFM (Netherlands) — all of which have active AML enforcement programs; (4) the crypto sector has seen multi-billion dollar AML fines (e.g., Binance $4.3B, BitMEX $100M); (5) MoonPay's role as a fiat-to-crypto on-ramp makes it a high-risk vector for money laundering. Risk is High not because MoonPay is non-compliant, but because the inherent regulatory risk in this sector is extremely high and enforcement consequences are severe.

Evidence: https://www.moonpay.com/legal/licenses, https://www.fincen.gov/msb-state-selector, https://fintrac-canafe.canada.ca/msb-esm/reg-eng, https://register.fca.org.uk/s/firm?id=0014G00002bpd05QAA, https://www.afm.nl/en/sector/registers/vergunningenregisters/cryptopartijen, https://www.moonpay.com/about-us

CMMC — Assessment Required

MoonPay displays a CMMC badge on its security page, which is unusual for a crypto financial services company as CMMC is primarily a US Department of Defense (DoD) contractor requirement. Risk is Low because CMMC is not a standard regulatory requirement for financial services companies, and its presence on MoonPay's security page may indicate a voluntary adoption or a specific government/institutional client requirement rather than a mandatory compliance obligation.

Evidence: https://www.moonpay.com/security

Financials

Three-year financials

Financial Resilience Score: 6/10

MoonPay demonstrates moderate financial resilience underpinned by a strong capital base (over US$620M raised across funding rounds), broad regulatory licensing across the US, UK, EU, Canada, and Australia, and a diversified partner network of approximately 500 B2B integrations. Management has publicly claimed a return to operating profitability in 2023, which sets it apart from many crypto peers that remain loss-making. However, the business is highly cyclical and closely correlated to crypto market activity. Revenue reportedly contracted in 2022 during the crypto winter, forcing layoffs of 20-25% of staff in early 2023. The company faces significant regulatory risk from evolving crypto rules (SEC, MiCA, FCA), fee compression from competitors like Stripe, Coinbase Onramp, and Robinhood, and counterparty concentration risk (historical NFT/OpenSea exposure). Disclosure opacity is a material weakness—as a private company with no audited group accounts publicly available, external stakeholders cannot fully verify profitability or solvency claims. Valuation history reflects volatility: peaked at US$3.4B in November 2021, fell to a reported US$1.5B secondary tender in 2022-2023, then recovered in 2025. Product diversification into stablecoins, institutional trading, and AI-agent infrastructure provides some resilience against on-ramp fee compression.

Key strengths: Over US$620M raised in equity from top-tier investors (Tiger Global, Coatue, Blossom, Thrive), Licensed across US, UK, EU, Canada, and Australia—significant regulatory moat, ~500 B2B partner integrations creating distribution flywheel, Reported return to profitability in 2023 per management, Product diversification into stablecoins, institutional, and AI-agent infrastructure, 180 countries supported, 170+ crypto assets

Risk factors: Revenue highly cyclical and correlated to crypto market activity, Regulatory risk from evolving US, EU (MiCA), and UK (FCA) crypto rules, Take-rate compression from competitors (Stripe, Coinbase Onramp, Robinhood, MetaMask), Historical partner concentration risk (NFT/OpenSea exposure collapsed in 2022), Opaque financial disclosure—no audited group accounts available, FX and banking-partner dependency (Visa/Mastercard, fiat settlement partners), Down-round history: valuation fell from US$3.4B (2021) to ~US$1.5B (2022-2023)

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report