OVH SAS
France · www.ovhcloud.com · 11 vendors
OVH SAS, operating as OVHcloud, is a French cloud computing company that provides public and private cloud products, dedicated servers, web hosting, and other web services globally. Founded in 1999, the company is known for its vertically integrated infrastructure and extensive network of data centers across four continents. It serves over 1.6 million customers worldwide, offering high-performance and cost-effective solutions for managing, protecting, and scaling data.
Resilience scores
- Digital Sovereignty: 9
- Digital Resilience: 6
- Financial Resilience: 6
Disruption prediction
OVH SAS has an estimated 27% probability of disruption in the next 6 months.
8 of OVH SAS's 11 vendors monitored for disruptions.
Technology vendors
- Google LLC — Technology — United States
- Meta Platforms, Inc. — Technology — United States
- Panasonic Avionics Corporation — Transport & Logistics — United States
- and 9 more
Services catalogue
18 services in catalogue across 5 categories; runs on 11 sub-vendors.
- Personal Data Processing
- OVHcloud Web Hosting
- API for saving consent data
Insights
Last updated 2026-08-10 · revision 20
11 direct vendors, 201 subvendors
Direct vendors by controlling owner country (sample)
- United States: 9
- Belgium: 1
- Japan: 1
Subvendors by controlling owner country (sample)
- France: 9
- Australia: 2
- Spain: 2
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
OVH SAS exhibits a high level of migration readiness, primarily driven by its modern, open-source, and cloud-native technology stack. The company's offerings are built on flexible platforms like OpenStack and Kubernetes, supporting containerization, microservices, and API-driven development. Its extensive product portfolio includes Public Cloud, Managed Kubernetes, Managed Databases, and AI/ML services, facilitating the adoption of modern application architectures. Hybrid cloud capabilities are strong, with Hosted Private Cloud options (VMware, Nutanix) and OVHcloud Connect for seamless on-premises integration. A key strength for OVH SAS's own migration readiness is its extreme vertical integration ('Total Vendors: 0'), which implies minimal external vendor lock-in for its core infrastructure, allowing for greater internal control and flexibility in evolving its platform. For customers, the use of open standards (OpenStack, Kubernetes) reduces potential lock-in when migrating to or from OVHcloud. Global data center presence and region selection tools provide flexibility for meeting diverse data residency requirements, including specific certifications like HDS for French health data. Financial stability further supports ongoing investment in platform development. The primary challenge to migration readiness stems from the complex and evolving regulatory landscape. Emerging regulations such as NIS2, CSRD, EU AI Act, SecNumCloud, and EUCS, while not fully assessed, are likely to impose stringent requirements on data sovereignty, security controls, and operational processes. These could necessitate significant planning, re-architecting, or restrict certain migration paths, particularly for sensitive workloads or those requiring immunity from non-EU legal frameworks (e.g., US CLOUD Act considerations for US data centers).
Compliance
12 in-scope frameworks identified; showing 3.
GDPR (source) — Compliant
OVH SAS is headquartered in Roubaix, France — an EU member state — making GDPR universally and unconditionally applicable. As a major cloud infrastructure provider (IaaS), OVH SAS processes vast quantities of personal data both as a Data Controller (employee data, customer account data, billing data) and as a Data Processor (customer workloads hosted on its infrastructure). The risk level is assessed as Medium rather than Low because: (1) the scale and complexity of data processing across 46 data centers on 4 continents creates inherent compliance complexity; (2) OVH SAS serves over 1.5 million customers globally, amplifying the volume of personal data processed; (3) cross-border data transfers (e.g., to US data centers) require ongoing SCCs/adequacy mechanism management; (4) the CNIL (France's DPA) is an active enforcement authority. However, OVH SAS publicly demonstrates strong GDPR commitment through ISO 27701 certification (privacy information management), a dedicated personal data protection portal, and published DPA agreements, reducing the likelihood of material non-compliance.
Evidence: https://us.ovhcloud.com/compliance/iso-27701/, https://us.ovhcloud.com/compliance/, https://us.ovhcloud.com/personal-data-protection/security/, https://www.ovhcloud.com/en/personal-data-protection/
CSA STAR — Compliant
OVH SAS participates in the CSA STAR program through a Self-Assessment, which is the entry-level tier of the CSA STAR program. The risk level is Low because: (1) CSA STAR is a voluntary program and OVH SAS has proactively completed the self-assessment; (2) the CSA STAR Self-Assessment (Level 1) demonstrates transparency about cloud security controls through the Consensus Assessments Initiative Questionnaire (CAIQ); (3) this is supplemented by OVH SAS's stronger mandatory certifications (ISO 27001, SOC 2). The primary limitation is that CSA STAR Self-Assessment is self-reported rather than independently audited.
Evidence: https://us.ovhcloud.com/compliance/, https://cloudsecurityalliance.org/star/registry
ISO 27001 (source) — Compliant
OVH SAS holds active ISO/IEC 27001:2022 certification, the latest version of the standard, issued by Schellman (an accredited third-party certification body). The risk level is Low because: (1) certification is current and independently verified; (2) ISO 27001 requires annual surveillance audits and triennial recertification, ensuring ongoing compliance; (3) OVH SAS has extended its ISMS to also cover ISO 27017 (cloud security controls) and ISO 27018 (protection of PII in public clouds), demonstrating comprehensive information security governance; (4) the certificate is publicly verifiable through Schellman's certificate directory. The primary residual risk is scope limitations — not all OVH SAS services or data centers may be within the certified scope.
Evidence: https://us.ovhcloud.com/compliance/iso-27001-27017-27018/, https://us.ovhcloud.com/compliance/, https://www.schellman.com/certificate-directory?certificateNumber=1670797-22
Financials
Three-year financials
- 2024: revenue €993M, equity €900M
- 2023: revenue €897M, equity €975M
- 2022: revenue €788M, equity €1.05B
Financial Resilience Score: 6/10
OVHcloud demonstrates solid operational resilience through its recurring subscription-based revenue model and strong Adjusted EBITDA margins near 38-39%, well above most hyperscaler resale models. The company benefits from vertical integration, designing and manufacturing its own servers and building/owning most data centers, which provides structural cost advantages. Its European sovereignty positioning aligns favorably with EU regulatory tailwinds including GAIA-X, Cloud de Confiance, NIS2, and DORA, making it attractive to public sector, banks, and healthcare organizations. The founder-controlled ownership structure (Klaba family retaining majority voting rights) supports long-term strategic orientation. However, financial resilience is constrained by high capital intensity, with heavy capex on data centers, servers, and network leading to elevated depreciation and amortization that suppresses EBIT and free cash flow. Statutory EBIT has been thin or slightly negative, and net results have typically been negative or near zero over FY2022-FY2024. The group carries meaningful net debt post-IPO with leverage around 2x Net debt/adjusted EBITDA. Scale disadvantage versus hyperscalers (AWS, Azure, Google Cloud) remains a competitive concern, and the share price has traded well below the €18.50 IPO price, limiting equity-financed acquisitions.
Key strengths: Recurring, subscription-like revenue with high gross retention, Adjusted EBITDA margins near 38-39%, Vertical integration with self-manufactured servers and owned data centers, European sovereignty positioning benefiting from EU regulatory tailwinds, Founder-controlled with long-term strategic orientation, Diversified product mix across Bare Metal, Private Cloud, and Public Cloud, 1.6+ million customers across 140+ countries with no material single-customer concentration
Risk factors: High capital intensity leading to negative or slim free cash flow, Scale disadvantage vs hyperscalers (AWS, Azure, Google Cloud), Operational/concentration risk highlighted by March 2021 SBG2 data-center fire, FX exposure as international revenue expands (USD, CAD, GBP), Meaningful net debt post-IPO with leverage around 2x Net debt/adjusted EBITDA, Share price trading well below IPO price of €18.50, Statutory EBIT thin or slightly negative due to high D&A
Revenue by geography
- France: 49%
- Europe excl. France: 26%
- Rest of World: 25%
Revenue by product/service
- Private Cloud: 60%
- Public Cloud: 20%
- Web Cloud & Other: 20%
Workforce by country
- France: 2000
- Rest of Europe: 400
- North America: 300
- Asia-Pacific: 150
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.