F5, Inc.

United States · owned by Independent (United States) · www.nginx.com · 36 vendors

F5, Inc. is a Seattle-based technology company that delivers application delivery and security solutions, operating nginx.com as the home of its NGINX product line — a widely used open-source web server, reverse proxy, and load balancer. F5 acquired NGINX, Inc. in 2019 and has since integrated NGINX into its broader Application Delivery and Security Platform (ADSP), offering cloud-native networking, API gateway, and security capabilities. Over 80% of the Fortune Global 500 rely on F5 to ensure their applications and APIs are fast, available, and secure.

Resilience scores

Disruption prediction

F5, Inc. has an estimated 27% probability of disruption in the next 6 months.

14 of F5, Inc.'s 36 vendors monitored for disruptions.

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 36 sub-vendors.

Insights

Last updated 2026-07-30 · revision 4

36 direct vendors, 303 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 10/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

F5, Inc. (NGINX) exhibits very high migration readiness. Their internal tech stack is overwhelmingly cloud-native and modern, with extensive utilization of major public cloud providers (AWS, Microsoft Azure, Google Cloud Platform), containerization technologies (Kubernetes, Docker), and service mesh architectures (Istio, Linkerd). This foundation, coupled with their own NGINXaaS offerings for Azure and Google Cloud, demonstrates deep expertise in hybrid and multi-cloud environments, significantly simplifying potential migrations. The company's strong financial stability, as part of F5 Networks, ensures ample resources to fund and execute complex migration initiatives. Furthermore, their comprehensive regulatory compliance experience (ISO 27001, SOC 2, GDPR, HIPAA, PCI DSS, FedRAMP, NIS2) means they are well-equipped to manage compliance requirements throughout any migration process. Flexible data residency options for NGINXaaS also provide significant adaptability. While 'Vendor Lock-in Risk: Unknown' is noted, their strategic adoption of open-source technologies (NGINX Open Source, Kubernetes) and adherence to standards like the Gateway API, along with a multi-cloud approach, inherently reduces proprietary vendor lock-in. The 'Total Vendors: 0' data point, if interpreted as minimal direct external vendor dependencies for core operations, would further enhance migration readiness by reducing external complexities. The primary opportunity lies in leveraging their existing cloud-native expertise and multi-cloud strategy for seamless transitions.

Compliance

12 in-scope frameworks identified; showing 3.

Section 508 — Compliant

F5 has published multiple Voluntary Product Accessibility Templates (VPATs) for its major products including BIG-IP v15.1, v16.1, v17.1, v17.5, BIG-IQ v8.4, F5 Distributed Cloud Console, F5OS v1.8.1, NGINX Plus R33, and NGINX Management Suite. This demonstrates active compliance with Section 508 accessibility requirements for federal procurement.

Evidence: https://www.f5.com/company/certifications, https://cdn.sanity.io/files/k6fem79d/production/651c2c09cdb7bed42900eb045625113075b38cc7.pdf

Common Criteria — Compliant

F5 holds multiple current Common Criteria certifications for BIG-IP products (versions 14.x through 17.5), certified under CCRA by Sweden (CSEC). Products are listed on the NIAP Product Compliant List and the NSA CSfC Components List. This demonstrates rigorous third-party security evaluation. Risk is Low given the breadth and currency of certifications.

Evidence: https://www.f5.com/company/certifications, https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/CCRA%20certificate%20F5%20BIG-IP%2017.5.0%20incl.APM.pdf, https://www.niap-ccevs.org/products, https://www.nsa.gov/Resources/Commercial-Solutions-for-Classified-Program/Components-List/

CPRA — Compliant

F5 is headquartered in Seattle, Washington, and operates extensively in California (major tech hub). F5 explicitly addresses CCPA/CPRA compliance on its privacy pages, provides a dedicated California Privacy Notice, offers a 'Do Not Sell My Personal Information' opt-out mechanism via OneTrust, and maintains a California-specific DSR portal. F5 clearly meets the CCPA applicability thresholds (annual gross revenue exceeding $25M, processes personal information of 100,000+ California consumers/households). Risk is Low because F5 has implemented the required CCPA/CPRA mechanisms and disclosures.

Evidence: https://www.f5.com/company/policies/privacy-compliance-and-practices, https://www.f5.com/company/policies/privacy-notice, https://privacyportal.onetrust.com/webform/86c88b66-1c6e-4a7d-8530-6d754439e01a/45381ea3-ec70-4d89-a08e-7633b8fdc40a

Financials

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report