PayPal Holdings, Inc.

United States · owned by Independent (United States) · www.paypal.com · 25 vendors

PayPal Holdings, Inc. is a leading global digital payments platform that enables individuals and businesses to send and receive money online securely. It offers a wide range of services including online payments, peer-to-peer transfers (via Venmo and PayPal), buy-now-pay-later (Pay Later), and merchant payment solutions. Headquartered in San Jose, California, PayPal operates in over 200 markets worldwide and serves hundreds of millions of active accounts.

Resilience scores

Disruption prediction

PayPal Holdings, Inc. has a 35% probability of disruption in the next 6 months.

15 of PayPal Holdings, Inc.'s 25 vendors monitored for disruptions.

Technology vendors

Services catalogue

21 services in catalogue across 6 categories; runs on 25 sub-vendors.

Insights

Last updated 2026-09-13 · revision 2

25 direct vendors, 265 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

PayPal exhibits high migration readiness, primarily driven by its advanced and cloud-native-friendly technology stack. The extensive use of Node.js, Java, JavaScript, React, Kubernetes, Docker, Apache Kafka, and a strong API-first approach (REST, GraphQL) signifies a highly modular, containerized, and distributed architecture that is well-suited for migration to modern cloud environments. The company's strong financial health, evidenced by consistent revenue growth, provides the necessary capital to fund complex migration initiatives. However, several factors introduce complexity to migration efforts. PayPal operates in a highly regulated environment, necessitating meticulous planning to ensure continuous compliance with PCI DSS, GDPR, AML, KYC, PSD2, and other national financial services licenses throughout any migration. Global data residency requirements, which PayPal currently addresses through globally distributed data centers, will also be a significant consideration, requiring careful architectural design to maintain data sovereignty in a new environment. The vendor relationship data is ambiguous; while 'Total Vendors: 0' is stated, other vendor-related fields exist. If there are indeed external vendors for the 31 services, the 'unknown' vendor lock-in risk could pose a challenge, though the internal tech stack suggests a high degree of portability that would mitigate some external dependencies. The geographic diversity of vendor locations (US, Japan, Canada, Australia, Sweden) is a positive, indicating less concentration risk from a geographic perspective.

Compliance

17 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

NIS2 is highly likely to apply to PayPal's EU operations. PayPal (Europe) S.à r.l. et Cie, S.C.A. operates as a licensed e-money institution and payment institution in Luxembourg, providing financial services across the EU. Under NIS2 (Directive 2022/2555), 'banking' and 'financial market infrastructures' are classified as Essential Entities (Annex I). Digital payment service providers and e-money institutions of PayPal's scale (tens of millions of EU users, billions in EU payment volume) clearly exceed the medium enterprise threshold (50+ employees, €10M+ turnover). Risk is rated High because: (1) NIS2 imposes strict cybersecurity risk management obligations, incident reporting (24-hour initial notification), supply chain security, and management accountability; (2) non-compliance penalties can reach €10M or 2% of global annual turnover; (3) NIS2 was transposed into national law by October 2024 and enforcement is active; (4) PayPal's role as critical payment infrastructure makes it a prime regulatory focus; (5) management personal liability provisions under NIS2 add additional risk dimension. Status is 'Assessment Required' because formal NIS2 registration/designation status across all EU member states has not been publicly confirmed.

Evidence: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.cssf.lu/en/2023/01/cssf-circular-22-806/, https://investor.paypal-corp.com/sec-filings/annual-reports, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554, https://www.cssf.lu/en/supervision/payment-institutions-electronic-money-institutions/

CPRA — Compliant

PayPal is headquartered in San Jose, California, and processes personal data of millions of California residents. CCPA/CPRA applies with full force. Risk is rated Medium because: (1) PayPal is a large business clearly exceeding CCPA thresholds (annual gross revenues >$25M, processes data of >100,000 consumers); (2) CPRA enforcement by the California Privacy Protection Agency (CPPA) is active; (3) PayPal's financial data processing creates heightened sensitivity under CCPA's 'sensitive personal information' provisions; (4) CCPA's private right of action for data breaches creates litigation exposure. PayPal has published a California-specific privacy notice and opt-out mechanisms.

Evidence: https://www.paypal.com/us/webapps/mpp/ua/privacy-full, https://www.paypal.com/us/webapps/mpp/ua/ccpa-privacy, https://cppa.ca.gov/, https://investor.paypal-corp.com/sec-filings/annual-reports

ISO 27001 (source) — Assessment Required

ISO 27001 certification is relevant to PayPal given its role as a global financial services platform handling sensitive financial and personal data. Risk is rated Medium because: (1) while ISO 27001 is not legally mandated for PayPal, it is increasingly expected by enterprise customers, regulators, and partners; (2) PayPal's EU operations under DORA and NIS2 benefit from ISO 27001 alignment; (3) lack of certification could affect enterprise sales and regulatory assessments; (4) PayPal's scale and complexity make certification challenging but achievable. Status is 'Assessment Required' because public confirmation of ISO 27001 certification for PayPal's global or EU operations has not been definitively confirmed in publicly available sources.

Evidence: https://www.paypal.com/us/business/security, https://www.iso.org/isoiec-27001-information-security.html, https://investor.paypal-corp.com/sec-filings/annual-reports

Financials

Three-year financials

Financial Resilience Score: 8/10

PayPal demonstrates strong financial resilience underpinned by multi-billion-dollar annual free cash flow generation (approximately $4.2B in FY2023 and guided ~$6B in FY2024), a solid balance sheet with roughly $16-17B in cash and investments against $11-12B of long-term debt, and investment-grade credit ratings (S&P A-, Moody's A3 area). The company's two-sided network moat, with 35M+ merchants accepting PayPal, Venmo, and Braintree, provides durable competitive positioning and diversified revenue streams across branded checkout, unbranded processing, P2P payments, remittances, and value-added services. Revenue growth has decelerated from ~20% during the pandemic to high-single digits (7-8%), and operating margin has stabilized around 16-17% after expansion in 2023. Elevated interest rates have provided a meaningful tailwind through customer balance interest income (~$1.5B+ annually). The company continues to return significant capital to shareholders via buybacks (~$5B in 2023, ~$6B in 2024). Key vulnerabilities include take-rate compression from Braintree unbranded mix shift (from ~1.86% in 2022 to ~1.70% in 2024), intensifying competition at checkout from Apple Pay, Shop Pay, Stripe, Adyen, and BNPL players, and essentially flat active-account growth. The turnaround under new CEO Alex Chriss is still unproven, and the market cap has declined from a $360B peak in 2021 to $70-90B range in 2024, reflecting multiple compression despite continued fundamental growth.

Key strengths: Multi-billion-dollar annual free cash flow generation (~$4.2B FY2023, ~$6B FY2024 guided), Strong balance sheet: ~$16-17B cash/investments vs. ~$11-12B long-term debt, Investment-grade credit ratings (S&P A-, Moody's A3 area), Two-sided network moat with 35M+ merchants globally, Diversified revenue across branded checkout, Braintree, Venmo, Xoom, Hyperwallet, Zettle, Interest income tailwind from customer balances (~$1.5B+ annually), Large capital returns via buybacks (~$5B in 2023, ~$6B in 2024), TPV growth from $1.36T (2022) to $1.68T (2024)

Risk factors: Take-rate compression from Braintree unbranded processing mix shift, Competitive pressure at checkout from Apple Pay, Shop Pay, Google Pay, Stripe, Adyen, Klarna, Affirm, Slowing/flat active-account growth (~426M-434M range), Regulatory exposure (CFPB, EU DMA/PSD3, UK FCA, state money-transmitter licensing), Consumer and merchant credit risk from BNPL and business loan portfolios, FX exposure with ~40%+ of revenue non-US, Turnaround execution risk under new CEO Alex Chriss, Pending litigation around Honey (2024) and anti-competitive-parity allegations

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report