NEC Corporation

Japan · www.nec.com · 21 vendors

NEC Corporation is a Japanese multinational information technology and electronics company headquartered in Tokyo, Japan. It provides IT and network solutions, including cloud computing, artificial intelligence, IoT platforms, and telecommunications equipment and software to businesses, communication service providers, and government agencies. The company also focuses on social infrastructure, offering solutions for public safety, digital government, and biometric authentication.

Resilience scores

Disruption prediction

NEC Corporation has an estimated 11% probability of disruption in the next 6 months.

12 of NEC Corporation's 21 vendors monitored for disruptions.

Technology vendors

Services catalogue

25 services in catalogue across 8 categories; runs on 21 sub-vendors.

Insights

Last updated 2026-07-13 · revision 14

21 direct vendors, 266 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

NEC Corporation exhibits a strong technical foundation for migration readiness, earning a score of 65 out of 100. The internal tech stack is highly modern, featuring Cloud-Native Architecture (Kubernetes-based container orchestration), Docker, and robust CI/CD Pipelines, which are crucial for efficient cloud migration and adoption of microservices. The company's financial stability, with generally increasing revenue, suggests adequate resources to fund complex migration initiatives. However, several factors present significant challenges. NEC faces complex and stringent data residency requirements across multiple jurisdictions, including EU GDPR, mainland China, and Japan, as well as sector-specific demands for government and critical infrastructure clients. These requirements will necessitate careful planning, potentially increasing the complexity and cost of data migration and infrastructure deployment. Additionally, while NEC's internal security governance is robust, the 'Assessment Required' status for NIS2, SOC2, and ISO 27001 indicates that achieving or maintaining these certifications will be a critical consideration during and after migration to new environments. The vendor lock-in risk is explicitly 'Unknown' in the provided data, but the moderate geographic diversity of vendor HQ countries (United States, Australia, Japan) for 28 listed services implies some level of external dependency that would need to be strategically managed during any large-scale migration effort.

Compliance

12 in-scope frameworks identified; showing 3.

APPI — Compliant

NEC Corporation is headquartered in Japan and is directly subject to Japan's APPI, which was significantly amended in 2022. NEC's Privacy Notice explicitly states compliance with 'laws, regulations and guidelines of Japan pertaining to the protection of personal information' and references JISQ 15001 certification — the Japanese Industrial Standard for personal information protection management systems. The risk is Low because NEC has demonstrated active compliance through JISQ 15001 certification and explicit policy commitments, and as a major Japanese corporation, APPI compliance is a core operational requirement.

Evidence: https://www.nec.com/en/global/privacy/index.html, https://www.nec.com/en/global/about/index.html

PIPL — Assessment Required

NEC has operations in China and its Privacy Notice explicitly addresses mainland China data transfers, stating: 'If you are located in mainland China, you understand that we may transfer the Personal Data we collect about you to recipients in countries or regions other than mainland China.' This confirms NEC processes personal data of Chinese residents. China's PIPL (effective November 2021) imposes strict requirements on cross-border data transfers, including security assessments for large-scale transfers and Standard Contract filings. The risk is Medium because PIPL enforcement has been active and cross-border transfer requirements are complex.

Evidence: https://www.nec.com/en/global/privacy/index.html

CPRA — Partially Compliant

NEC has US operations and processes personal information of California residents. NEC's Privacy Notice includes a dedicated Section 12 'Notice to residents in the United States' addressing CCPA/CPRA requirements. The risk is Medium because NEC's US operations are substantial (NEC Corporation of America), and CCPA/CPRA enforcement by the California Privacy Protection Agency (CPPA) has been increasing. NEC's notice addresses key CCPA rights but the complexity of NEC's data processing activities (biometrics, AI, government solutions) creates ongoing compliance challenges.

Evidence: https://www.nec.com/en/global/privacy/index.html, https://www.nec.com/en/global/cookies/index.html

Financials

Three-year financials

Financial Resilience Score: 8/10

NEC Corporation demonstrates strong financial resilience, driven by a significant profitability transformation over the past several years. Non-GAAP operating profit has grown from ¥150.9B (FY2021) to ¥311.3B (FY2025), with the non-GAAP operating margin nearly doubling from 5.0% to 9.1%. IFRS operating profit surged 36.4% in FY2025 to ¥256.5B and net profit reached ¥175.2B, while ROE improved to 9.1%. The balance sheet has strengthened materially, with owners' equity ratio rising from ~29% (FY2020) to 45.2% (FY2025) and a low D/E ratio of 0.34x. Cash generation is robust: operating cash flow of ¥344.4B and free cash flow of ¥213.2B in FY2025 support both increased capex (¥116.1B) and higher shareholder returns (dividend raised from ¥110 to ¥140 per share). NEC's mission-critical customer base (government, finance, telecom, defense) provides sticky revenue, and technology leadership in biometrics, submarine cables, and its ~43,000 patent portfolio underpin long-term competitiveness. However, resilience is tempered by weak top-line growth (10-year revenue CAGR of only ~2%), a declining international revenue ratio (27.0% in FY2023 down to 20.7% in FY2025), workforce contraction from 118,527 to 104,194 in two years due to divestitures/restructuring, and declining R&D spend (from ¥126.3B in FY2022 to ¥99.2B in FY2025). Concentration in Japan (~79% of revenue, ~72% of employees) exposes NEC to Japanese demographic and IT-spending cycles.

Key strengths: Non-GAAP operating margin doubled to record 9.1% in FY2025, Owners' equity ratio strengthened to 45.2% with low D/E of 0.34x, Strong free cash flow of ¥213.2B supporting capex and dividends, Mission-critical customer base in government, finance, telecom, defense, Technology leadership: #1 in biometric authentication, top share in submarine cables, ~43,000 patents, Net profit growth of 17.2% YoY to ¥175.2B; ROE up to 9.1%

Risk factors: Modest revenue growth (~2% 10-year CAGR); FY2025 revenue declined 1.5%, International revenue ratio declining from 27.0% (FY2023) to 20.7% (FY2025), Workforce contraction of ~14,000 in two years due to divestitures/restructuring, Declining R&D spend from ¥126.3B (FY2022) to ¥99.2B (FY2025), High concentration in Japan (~79% of revenue), Historical compliance incidents (bid-rigging cases 2016-2017), Geopolitical and cybersecurity risks flagged as high-impact by management, Quality/safety risk in defense and public-sector systems

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report