Nextcloud GmbH

Germany · nextcloud.com · 28 vendors

Nextcloud GmbH is a German company providing an open-source, self-hosted content collaboration platform. Its flagship product, Nextcloud Hub, offers secure file storage, synchronization, and sharing, alongside real-time document editing, communication tools, and groupware functionalities. The platform enables organizations to maintain control over their data and ensure compliance with privacy regulations.

Resilience scores

Disruption prediction

Nextcloud GmbH has an estimated 27% probability of disruption in the next 6 months.

11 of Nextcloud GmbH's 28 vendors monitored for disruptions.

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 28 sub-vendors.

Insights

Last updated 2026-08-15 · revision 2

28 direct vendors, 245 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Nextcloud GmbH exhibits good migration readiness, scoring 68. The company's adoption of containerization via Docker and support for cloud storage protocols like S3/Object Storage are key enablers for cloud migration. Their strong focus on compliance, evidenced by tooling for GDPR, HIPAA, and CCPA, is a significant advantage, as it suggests their systems are designed with portability and regulatory adherence in mind, simplifying migration to various regulated cloud environments. The open-source nature of their products also provides inherent flexibility for internal system migrations. While Nextcloud's core business model is centered around self-hosted and on-premises solutions, which might imply their internal infrastructure is not entirely cloud-native, the presence of modern web technologies (Vue.js, Node.js, WebAssembly) indicates adaptability. Limiting factors include the absence of data on their financial capacity to fund a major migration and the unknown vendor lock-in risk for their own operations. Additionally, the unspecified data residency requirements could introduce complexities if strict rules were to emerge during a migration process.

Compliance

11 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 is directly relevant to Nextcloud GmbH as a technology company providing information security-critical collaboration software to enterprise and government customers. Risk is Medium because: (1) Nextcloud's compliance page explicitly references 'several ISO certifications' as supported by Nextcloud Enterprise, and the EU Cybersecurity Act section references 'existing certifications like ISO 27001'; (2) the company's enterprise customer base (government agencies, financial institutions, critical infrastructure operators) typically mandates ISO 27001 certification from software vendors; (3) NIS2 compliance (likely applicable) is facilitated by ISO 27001 alignment; (4) however, it is unclear whether Nextcloud GmbH itself holds ISO 27001 certification vs. merely enabling customers to achieve it. The distinction between 'supporting ISO 27001 for customers' and 'holding ISO 27001 certification' is critical and not clearly resolved in public sources.

Evidence: https://nextcloud.com/compliance/, https://nextcloud.com/secure/, https://nextcloud.com/enterprise/

NIS2 (source) — Assessment Required

NIS2 (EU Directive 2022/2555, transposed into German law via BSIG-Novelle / NIS2UmsuCG) is highly likely applicable to Nextcloud GmbH based on multiple converging factors: (1) Nextcloud GmbH is established in Germany (EU member state); (2) the company operates in the 'digital infrastructure' and 'digital providers' sectors explicitly listed under NIS2 Annex I and II — specifically as a provider of cloud computing services and online marketplaces/platforms; (3) Nextcloud serves thousands of organizations globally including critical public sector entities (German Federal Administration ITZBund, Austrian Federal Ministry, Serbian Parliament, Deutsche Telekom, universities, municipalities); (4) the company's revenue and employee count likely exceed the NIS2 medium-enterprise threshold (50+ employees, €10M+ turnover) given its global enterprise customer base and decade-long operation. Risk is Medium rather than High because: Nextcloud's self-hosted model means customers operate the infrastructure, potentially shifting primary NIS2 obligations to deploying organizations; however, Nextcloud GmbH as a software/platform vendor providing ICT services to critical entities likely qualifies as an 'Important Entity' under NIS2 Annex II (digital providers). Germany's NIS2 transposition (NIS2UmsuCG) entered into force in 2024. Formal NIS2 registration and compliance assessment status is not publicly confirmed.

Evidence: https://nextcloud.com/compliance/, https://nextcloud.com/secure/, https://nextcloud.com/impressum/, https://nextcloud.com/about/

BDSG — Partially Compliant

The BDSG is the German national data protection law that supplements and implements GDPR in Germany. As a German GmbH headquartered in Stuttgart (Baden-Württemberg), Nextcloud GmbH is directly subject to BDSG. Risk is Medium because: (1) BDSG imposes additional obligations beyond GDPR, including specific rules on employee data processing (§26 BDSG), works council involvement in data processing decisions, and stricter requirements for certain sensitive data categories; (2) the company processes employee personal data under German employment law; (3) the Baden-Württemberg State Data Protection Authority (LfDI BW) has active enforcement jurisdiction; (4) Nextcloud's strong GDPR posture suggests BDSG alignment, but no specific BDSG compliance audit has been publicly confirmed.

Evidence: https://nextcloud.com/impressum/, https://nextcloud.com/compliance/, https://www.gesetze-im-internet.de/bdsg_2018/

Financials

Three-year financials

Financial Resilience Score: 7/10

Nextcloud GmbH demonstrates solid financial resilience despite limited public disclosure. As a founder-led, self-funded German GmbH, the company has publicly stated it has been profitable and cash-flow positive since around 2019-2020, avoiding the venture-debt overhang common to growth-stage software companies. Management has cited triple-digit percentage growth in enterprise revenue following the 2020 pandemic-driven demand surge, and the company has grown to over 400,000 known deployments serving tens of millions of end users. The company benefits from a diversified, sticky customer base heavily weighted toward public sector clients including the German Federal IT Center (ITZBund), the German Federal Administration (Bundescloud with 500,000+ users), Deutsche Telekom, and multiple European government bodies. These multi-year recurring contracts provide revenue predictability. The structural tailwind from EU/German digital sovereignty initiatives to reduce dependence on US hyperscalers represents a durable growth driver. However, the small-company disclosure regime limits external transparency, which could hamper large procurement decisions. Customer concentration risk exists in large government tenders, and the open-source model creates conversion risk since the free product is fully functional. Competition from well-capitalized incumbents like Microsoft 365 and Google Workspace remains significant, though Nextcloud's open-source moat and community-driven development lower R&D costs relative to proprietary competitors.

Key strengths: Profitable and cash-flow positive since ~2019-2020, Self-funded with no venture-debt overhang, Diversified sticky public-sector customer base with multi-year contracts, EU/German digital sovereignty tailwind driving structural demand, Open-source moat lowering R&D costs, Founder-led with focus on profitability over burn-and-grow, Product breadth expansion via Roundcube acquisition (2024), Over 400,000 known deployments and tens of millions of end users

Risk factors: Competitive pressure from Microsoft 365, Google Workspace, Box, Dropbox, Customer concentration risk in large government tenders (e.g., Bundescloud), Limited external financial transparency as small GmbH, Open-source revenue conversion risk (free product is fully functional), Talent/wage inflation in German/European tech labor market, FX exposure on non-Euro revenue, Competition from other European sovereign-cloud initiatives

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report