OTRS Group
Germany · www.otrs.com · 21 vendors
Resilience scores
- Digital Sovereignty: 19
- Digital Resilience: 7
- Financial Resilience: 5
Technology vendors
- Demandware — Technology — United States
- HubSpot, Inc. — Technology — United States
- Netlify, Inc. — Technology — United States
- and 18 more
Services catalogue
2 services in catalogue across 2 categories; runs on 21 sub-vendors.
- OTRS Managed Service
- Personal Data Processing
Insights
Last updated 2026-07-02 · revision 2
21 direct vendors, 254 subvendors
Direct vendors by controlling owner country (sample)
- Italy: 1
- Ukraine: 1
- United States: 15
Subvendors by controlling owner country (sample)
- Belgium: 1
- South Korea: 1
- Czech Republic: 1
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
OTRS Group exhibits a medium level of migration readiness. A key strength is their existing use of Oracle Cloud Infrastructure (OCI), indicating some experience with public cloud environments. The availability of JSON/REST APIs, SOAP, and XSLT facilitates integration, which is crucial for migrating and modernizing applications. The company's adoption of an AI module and Node-RED for integration connectors suggests a willingness to embrace modern technologies and potentially a more modular architecture, though this is not explicitly stated for the core platform. Adherence to ITIL 4 also implies structured processes that can aid in managing a complex migration. However, the most significant challenge to migration readiness is the core OTRS platform's foundational reliance on Perl. Migrating a potentially monolithic application built on a legacy language like Perl to a modern cloud-native architecture (e.g., microservices, containers) would likely be a complex, time-consuming, and costly undertaking. There is no explicit mention of containerization or microservices for the core platform, suggesting a traditional architecture. Critical information regarding data residency requirements, the specific regulatory environment, and financial stability (ability to fund a large-scale migration) is missing, which are all vital considerations. While vendor geographic diversity is present, the actual number of vendors and the explicit vendor lock-in risk are unknown, making it difficult to fully assess this aspect. The overall readiness is constrained by the potential technical debt associated with the core platform's technology stack.
Compliance
8 in-scope frameworks identified; showing 3.
BSI C5 — Assessment Required
BSI C5 is a German Federal Office for Information Security (BSI) standard specifically designed for cloud service providers operating in Germany. OTRS AG is a German SaaS/cloud service provider, making BSI C5 directly relevant. Risk is Medium because: (1) OTRS's Trust Center explicitly references BSI C5 as a standard applied to its data centers; (2) German public sector customers and regulated industries increasingly require BSI C5 attestation from cloud providers; (3) if OTRS serves German government or critical infrastructure customers, BSI C5 attestation may be contractually required; (4) the reference to BSI C5 in the Trust Center suggests awareness but does not confirm that OTRS AG itself holds a BSI C5 attestation (as opposed to its data center providers).
Evidence: https://otrs.com/trust-center/, https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Empfehlungen-nach-Angriffszielen/Cloud-Computing/Kriterienkatalog-C5/kriterienkatalog-c5_node.html
SOC 2 (source) — Assessment Required
OTRS AG is a SaaS/cloud service provider, which is precisely the type of organization for which SOC 2 (Type I or Type II) reports are most relevant and commonly requested by enterprise customers. Risk is Medium because: (1) enterprise customers — particularly in regulated industries — increasingly require SOC 2 reports from their SaaS vendors as part of vendor due diligence; (2) absence of a publicly disclosed SOC 2 report may create a competitive disadvantage and procurement friction; (3) OTRS's Trust Center documents many security controls (encryption, access control, monitoring, vulnerability management) that align with SOC 2 Trust Service Criteria, but no SOC 2 report is publicly referenced; (4) without a SOC 2 report, customers cannot independently verify the operating effectiveness of OTRS's controls. Risk is not High because SOC 2 is a voluntary framework (not a legal requirement) and OTRS references ISO 27001 and BSI C5 for its data centers, which provide some assurance.
Evidence: https://otrs.com/trust-center/, https://www.hetzner.com/unternehmen/zertifizierung/, https://us.ovhcloud.com/enterprise/certification-conformity/, https://www.oracle.com/de/corporate/cloud-compliance/
NIS2 (source) — Assessment Required
NIS2 (EU Directive 2022/2555, transposed into German law via the NIS2UmsuCG) is potentially applicable to OTRS AG on two grounds: (1) As a 'digital provider' — specifically a provider of managed services / cloud computing services / online marketplaces — OTRS's SaaS and managed service offerings may qualify it as an 'Important Entity' under Annex II of NIS2; (2) As an ICT service management provider serving critical sectors, OTRS could be in scope. Risk is Medium because: the company is a mid-sized German software/SaaS company with global operations; NIS2 enforcement in Germany began with the NIS2UmsuCG transposition process (still ongoing as of 2024-2025); penalties for non-compliance can reach €10M or 2% of global turnover for Important Entities; however, the exact classification (whether OTRS meets the 'managed service provider' or 'cloud computing service' definition under NIS2 Annex II) requires a formal legal assessment. The company's size (publicly listed, international operations) likely exceeds the 50-employee / €10M turnover threshold. Risk is not rated High because OTRS is not in an Essential Entity sector (energy, transport, banking, health, etc.).
Evidence: https://otrs.com/trust-center/, https://otrs.com/otrs-software-solutions/otrs/, https://otrs.com/otrs-software-solutions/cyber-defense/, https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/NIS2/nis2_node.html
Financials
Three-year financials
- 2024: revenue EUR 12.08M, EBIT EUR -1.34M, equity EUR 2.72M
- 2023: revenue EUR 12.31M, EBIT EUR -1.57M, equity EUR 3.80M
- 2022: revenue EUR 11.84M, EBIT EUR 0.49M, equity EUR 5.07M
Financial Resilience Score: 5/10
OTRS AG shows a mixed resilience profile. On the positive side, the company enjoys a very high share of recurring revenue (90-94%), providing a predictable subscription-like top line. It carries no interest-bearing bank debt, has no pledged assets, and holds EUR 2.76M in cash at year-end 2024. The customer base is diversified with blue-chip references (BSI, Lufthansa, Bayer, Thyssenkrupp, European Commission, Porsche), and the annual up-front invoicing model generates strong deferred revenue balances (EUR 6.05M at end-2024) resulting in an adjusted quick ratio of 555%. However, financial performance has deteriorated significantly. Both 2023 and 2024 were loss-making, with equity falling from EUR 5.07M (2022) to EUR 2.72M (end-2024), and the equity ratio sliding from 36.6% to 27.4%. The personnel cost ratio has climbed from 55% (2022) to 68% (2024), and revenue per employee dropped from EUR 148K to EUR 127K. Consulting/services revenue was nearly halved in 2024. Dividends of EUR 192K p.a. continue to be paid despite losses, further eroding equity. The December 2024 acquisition by EasyVista SAS (>90% stake) introduces both strategic support from a larger European IT group and integration/restructuring risk. The auditor issued unqualified opinions in all three years with no going-concern qualifications. Overall, the company retains adequate short-term liquidity and a resilient recurring revenue model, but declining profitability, shrinking equity, and small absolute size warrant a moderate resilience score.
Key strengths: Very high recurring revenue share (94.5% in 2024), No interest-bearing bank debt and no pledged assets, EUR 2.76M cash on hand at end-2024, Diversified blue-chip customer base (BSI, Lufthansa, Bayer, Porsche, European Commission), Strong deferred revenue balance (EUR 6.05M) and adjusted quick ratio of 555%, Unqualified audit opinions across all three years, Backing of larger EasyVista group post-December 2024 takeover
Risk factors: Two consecutive years of losses (2023: EUR -1.08M; 2024: EUR -0.89M), Equity ratio declined from 36.6% (2022) to 27.4% (2024), Equity nearly halved from EUR 5.07M (2022) to EUR 2.72M (2024), Personnel cost ratio climbed from 55% to 68% of revenue, Consulting/services revenue dropped 42.7% in 2024, Revenue turned slightly negative in 2024 (-1.9%), Small absolute size (<EUR 13M revenue, ~95 staff), Continued dividend payments despite losses, Integration/squeeze-out risk following EasyVista majority takeover, High R&D intensity (~40% of sales) now fully expensed
Revenue by geography
- Germany: 71.2%
- Foreign (International): 28.8%
Revenue by product/service
- IT services & support (recurring/subscription): 94.5%
- Consulting services: 5.4%
- Other: 0.1%
Workforce by country
- Germany: 95
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.