Nebius B.V.

Netherlands · owned by Independent (Netherlands) · nebius.com · 60 vendors

Nebius builds vertically integrated AI infrastructure that accelerates AI innovation globally and at scale. With large-scale GPU clusters deployed across Europe and the US, Nebius's full-stack cloud platform combines the scale, flexibility and reliability of a hyperscaler with the power and performance of a supercomputer.

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 1 category; runs on 60 sub-vendors.

Insights

Last updated 2026-07-30 · revision 21

60 direct vendors, 422 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Nebius B.V. exhibits high migration readiness, scoring 85. Its modern and cloud-native tech stack is a primary strength, featuring managed Kubernetes, serverless AI offerings, and an OpenAI-compatible API layer, which promotes portability and reduces architectural dependencies. The use of open standards like PostgreSQL with pgvector further enhances flexibility. Financially, Nebius's rapid revenue growth (from $20.9M in 2023 to $529.8M projected in 2025) ensures it has the financial capacity to fund complex migration initiatives, whether for its own infrastructure or to support customer transitions. A significant advantage is Nebius's explicit commitment to customer data residency, allowing customers to select their preferred geographic region for data storage and processing (EU, Israel, US). This architectural design for data localization simplifies migration planning for customers with strict regulatory requirements. The company's comprehensive regulatory compliance (GDPR, HIPAA, ISOs, etc.) means it operates with high standards for data management and security, which are beneficial for structured and compliant migrations. The contradictory vendor data ('Total Vendors: 0' vs. 'Total Services: 83' from 12 countries) makes assessing internal vendor lock-in challenging. However, if Nebius indeed leverages a diverse set of vendors across 12 countries for its 83 services, this would generally indicate lower internal vendor lock-in for Nebius itself. A potential challenge for customers migrating *from* Nebius is the 'Vertically Integrated AI Infrastructure' and specialized NVIDIA hardware (e.g., GB300 NVL72, HGX B300). While offering high performance, these specialized components could lead to a degree of customer lock-in if an alternative provider cannot offer equivalent bare-metal performance or specific hardware configurations. The 'Vendor Lock-in Risk' for Nebius's own vendors remains 'Unknown', which is a minor blind spot. Overall, Nebius's modern architecture, financial strength, and commitment to data residency position it well for managing migrations.

Compliance

11 in-scope frameworks identified; showing 3.

SOC 2 (source) — Compliant

Nebius has obtained SOC 2 Type II certification (the more rigorous, audit-period-based version), which is directly confirmed on its Trust Center. SOC 2 Type II is the gold standard for cloud service providers and demonstrates that Nebius's security controls have been independently audited and found effective over a sustained period. Risk is Low because: (1) SOC 2 Type II certification is confirmed from an official company source; (2) Type II (vs. Type I) means controls were tested over time, not just at a point in time; (3) the certification includes HIPAA criteria, indicating a comprehensive audit scope; (4) a SOC 3 (public summary report) is also listed, indicating transparency; (5) Nebius also maintains multiple ISO certifications that complement and reinforce SOC 2 controls. The primary residual risk is that SOC 2 reports have annual renewal cycles and the current report's coverage period and auditor are not publicly disclosed.

Evidence: https://nebius.com/trust-center, https://nebius.com/trust-center/soc-2, https://nebius.com/trust-center/soc-3

ISO 27001 (source) — Compliant

Nebius has obtained ISO/IEC 27001 certification, confirmed directly on its Trust Center. ISO 27001 is the internationally recognized standard for Information Security Management Systems (ISMS). Risk is Low because: (1) ISO 27001 certification is confirmed from an official company source; (2) ISO 27001 requires annual surveillance audits and triennial recertification, ensuring ongoing compliance; (3) Nebius has obtained multiple related ISO certifications (27701, 27018, 27032, 27799, 22301), indicating a mature, comprehensive information security program; (4) the company's security-by-design and security-by-default principles align with ISO 27001 Annex A controls; (5) the combination of ISO 27001 + SOC 2 Type II provides dual-framework assurance. The primary residual risk is that the specific certification scope, issuing body, and certificate validity dates are not publicly disclosed.

Evidence: https://nebius.com/trust-center, https://nebius.com/trust-center/iso-27001, https://nebius.com/trust-center/iso-27701, https://nebius.com/trust-center/iso-27018, https://nebius.com/trust-center/iso-22301

HIPAA (source) — Compliant

HIPAA is applicable to Nebius in its capacity as a cloud infrastructure provider (Business Associate) for US healthcare customers. Nebius explicitly offers a 'SOC 2 Type II with HIPAA' certification and publishes a 'HIPAA Implementation Guideline' in its legal documentation, confirming active HIPAA compliance. The company serves healthcare customers (e.g., Sword Health is featured as a customer case study). Risk is Medium rather than Low because: (1) HIPAA violations carry significant penalties (up to $1.9M per violation category per year); (2) as a cloud provider, Nebius acts as a Business Associate and must execute BAAs with covered entities; (3) healthcare AI workloads (like Sword Health's 'Dawn' model with 10M+ sessions) involve sensitive PHI; (4) HIPAA enforcement by HHS OCR has been increasing, particularly for cloud providers. Risk is not High because Nebius has proactively obtained SOC 2 Type II with HIPAA attestation and published implementation guidelines.

Evidence: https://nebius.com/trust-center, https://nebius.com/trust-center/soc-2, https://docs.nebius.com/legal/hipaa, https://nebius.com/trust-center/iso-27799

Financials

Three-year financials

Financial Resilience Score: 7/10

Nebius Group N.V. demonstrates a paradoxical financial profile: exceptionally strong liquidity and equity backing combined with significant operating losses and aggressive capital expenditure. The company ended FY 2025 with $3.68bn in cash and $4.61bn in shareholders' equity, supported by a $4.16bn convertible note issuance, a $1.15bn equity raise in 2025, and a prior $700m raise in December 2024. This provides substantial runway to fund its hyper-growth strategy in AI infrastructure. Revenue growth has been extraordinary, expanding roughly 5x year-on-year for two consecutive years, reaching $529.8m in FY 2025 with ARR guidance of $750m–$1.0bn for end-2025. Deferred revenue surged from $16m to $1.58bn, indicating large multi-year prepaid customer commitments, including the Meta supply agreement valued at up to ~$27bn. Cost of revenues improved from 48% to 31% of revenue, showing improving unit economics. However, the company continues to burn cash heavily: FY 2025 operating loss was $(596m), adjusted EBITDA was $(65m), and adjusted net loss widened to $(447m). Capex exploded to $4.07bn (vs $0.81bn in 2024), and $4.10bn of non-current debt was added via convertible notes. The reported GAAP net profit of $29m is entirely attributable to a one-off $598.9m revaluation gain on the ClickHouse equity stake, masking the underlying operating burn. Key risks include customer concentration (Meta), NVIDIA GPU supply dependency, hyperscaler competition, a $180.9m Dutch withholding-tax contingent liability, and ongoing share-based compensation dilution. Overall, financial resilience is strong in the near term due to the cash cushion and contracted backlog, but long-term resilience depends on achieving operating profitability before liquidity is consumed by capex.

Key strengths: $3.68bn cash position at end-2025, $4.61bn shareholders' equity base, Revenue grew ~5x YoY to $529.8M in FY 2025, Deferred revenue surged to $1.58bn signalling large prepaid backlog, Meta supply agreement worth up to ~$27bn, Strategic anchor investors including NVIDIA, Accel, Orbis, NVIDIA Reference Platform Cloud Partner status, Cost of revenues improved from 48% to 31% of revenue, ARR guidance of $750M–$1.0bn for end-2025

Risk factors: Persistent operating losses: FY 2025 EBIT of -$596M, Adjusted net loss widened to -$447M in 2025, Massive capex burn of $4.07bn in 2025, $4.10bn in new convertible debt added in 2025, Customer concentration risk from Meta contract, NVIDIA GPU supply dependency and semi-cycle risk, Hyperscaler competition (AWS, Azure, GCP, Oracle, CoreWeave), $180.9M Dutch withholding-tax contingent liability, Share-based compensation dilution ($83.2M SBC in 2025), GAAP profit masked by one-off $599M equity revaluation gain

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report