Packet Clearing House

United States · www.pch.net · 3 vendors

Packet Clearing House (PCH) is an international organization that provides operational support and security to critical Internet infrastructure, including Internet exchange points (IXPs) and the core of the Domain Name System (DNS). It assists in building and supporting IXPs, operates the world's largest anycast DNS network, and conducts research and policy work related to Internet governance and economics.

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 3 sub-vendors.

Insights

Last updated 2026-08-04 · revision 7

3 direct vendors, 13 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 2/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Packet Clearing House (PCH) exhibits low migration readiness due to its highly specialized, physically embedded infrastructure, extreme regulatory and data residency complexities, and inherent internal lock-in. PCH's core services, such as IXP support and DNSSEC signing, are deeply integrated with physical hardware, including FIPS 140-2 Level 4 HSMs, Tier-4 datacenter infrastructure, GSA Class-5 IPS Security Containers, and SCIFs. This bespoke, hardware-dependent architecture is not inherently cloud-native or easily portable, making migration to a different operational paradigm (e.g., public cloud) exceptionally challenging and costly. The proprietary Adaptive DNS service further contributes to this technical lock-in. The regulatory environment is a significant impediment to migration. PCH operates 335+ PoPs across 20+ countries, subjecting it to a complex web of data protection and cybersecurity regulations, including GDPR, NIS2, India's DPDPA, Indonesia's UU PDP, Canada's PIPEDA, FCC, and ICANN. The stringent data residency requirements across these jurisdictions, coupled with the need to document cross-border transfer mechanisms (e.g., for GDPR), appoint EU representatives/DPOs, and ensure NIS2 registration, create immense complexity for any large-scale data or infrastructure migration. While the provided vendor data is contradictory ("Total Vendors: 0" but other vendor fields populated), interpreting it as high self-reliance means PCH is not locked into *external* vendor contracts. However, this implies a profound *internal* lock-in to its own highly customized, globally distributed, and physically embedded infrastructure. Migrating away from this bespoke setup would require a complete re-architecture and significant investment. Finally, the complete lack of financial data (revenue, employees) makes it impossible to assess PCH's capacity to fund a potentially multi-year, multi-million dollar migration effort. While the ISO 27001 certification indicates strong internal processes, which are beneficial for managing complex projects, the fundamental challenges posed by the tech stack, regulatory landscape, and internal lock-in severely limit migration readiness.

Compliance

9 in-scope frameworks identified; showing 3.

ISAE 3000 (source) — Assessment Required

ISAE 3000 is relevant when organizations provide assurance reports to third parties about their controls or processes. PCH's role as a critical infrastructure provider to hundreds of registries and IXPs globally could create demand for ISAE 3000 assurance reporting (e.g., as an alternative to SOC 2 for non-US customers). However, PCH is a non-profit intergovernmental organization, not a commercial assurance services provider, and there is no public evidence that ISAE 3000 reporting is required by its customers or regulators. Risk is Low because PCH's ISO 27001 certification provides a widely recognized alternative assurance mechanism.

Evidence: https://www.pch.net/about/privacy, https://www.pch.net/about/trust

ICANN Contractual Compliance — Assessment Required

PCH hosts nearly 400 top-level domains and provides authoritative DNS services to domain name registries globally. Registries operating under ICANN contracts (gTLDs and some ccTLDs) are subject to ICANN's Registry Agreement requirements, including data escrow, WHOIS/RDAP obligations, and security requirements. PCH, as a technical service provider to these registries, may be subject to ICANN's technical requirements and could be indirectly affected by registry compliance obligations. Risk is Medium because non-compliance by PCH's registry customers could implicate PCH's service delivery, and ICANN's evolving data governance requirements (post-GDPR WHOIS reform) directly affect DNS operations.

Evidence: https://www.pch.net/services/anycast, https://www.pch.net/services/dnssec, https://www.pch.net/services/policy

SOC 2 (source) — Assessment Required

PCH provides critical infrastructure services (authoritative DNS, DNSSEC signing, IXP support) to hundreds of organizations globally, including domain name registries and IXP operators who rely on PCH's availability, security, and confidentiality controls. These service relationships create a strong business case for SOC 2 Type II attestation, as PCH's customers (registries, IXPs) may require assurance over PCH's controls as part of their own compliance programs. Risk is Medium because: (1) absence of SOC 2 may create vendor risk management gaps for PCH's enterprise customers; (2) PCH's ISO 27001 certification partially addresses the same control domains; (3) PCH is a non-profit with limited resources, making SOC 2 engagement less certain; (4) no contractual SOC 2 requirement is publicly documented.

Evidence: https://www.pch.net/about/privacy, https://www.pch.net/about/trust, https://www.pch.net/services/dnssec

Financials

Three-year financials

Financial Resilience Score: 6/10

Packet Clearing House (PCH) is a 30-year-old non-profit organization with strong mission legitimacy and a diversified funding base that includes hundreds of private-sector donors, multiple governments, and in-kind contributions of power, fiber, servers, and colocation from partner IXPs and datacenters. Its August 2023 transition to an intergovernmental treaty organization provides a new legal framework for recurring government contributions, potentially stabilizing long-term funding similar to organizations like ICANN. The in-kind funding model significantly reduces cash requirements for infrastructure operations. However, financial resilience assessment is hampered by significant opacity — PCH's published annual reports do not include financial statements, revenue figures, expenses, or net assets. As a former US 501(c)(3), historical Form 990 filings would be the primary financial source but were not accessible in this research. PCH provides services free of charge, meaning there is no fee-based recurring revenue floor, making it entirely dependent on donor and government generosity. The initial treaty base of only four small African economies (Rwanda, Gambia, Guinea, Eswatini) suggests modest assessed contributions, with scaling dependent on additional signatories. Key-person dependency on Secretary General Bill Woodcock and the complexity of the 501(c)(3) to IGO transition add additional risk factors.

Key strengths: Diversified donor base with hundreds of private-sector donors plus multiple governments, In-kind funding model (donated power, fiber, servers, colocation) reduces cash needs, New intergovernmental treaty status (August 2023) provides framework for recurring government contributions, 30-year operational track record since 1994 with strong mission legitimacy, Operates D-root and E-root DNS anycast creating high barriers to substitution, Broad geographical footprint with 300+ anycast sites across many countries, Significant operational scaling in 2024 (D-root sites +38%, E-root +42%, IPv4 peering +33%)

Risk factors: No public financial statements — significant opacity to third parties, Grant/donation dependency with no paying customer revenue floor, Legal transition risk from US 501(c)(3) to IGO status, Small initial treaty base (only 4 small African economies as founding signatories), Key-person dependency on Secretary General Bill Woodcock, In-kind funding creates dependency on continued goodwill of specific IXP and datacenter partners, Historic Form 990 reporting may cease with unclear replacement reporting standard

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report