Ping Identity

United States · www.pingidentity.com · 12 vendors

Ping Identity provides intelligent identity solutions for the enterprise, offering identity and access management (IAM) platforms. Their solutions include single sign-on (SSO), multi-factor authentication (MFA), access security, directory services, and fraud detection. The company enables secure and seamless digital experiences for employees, partners, and customers across cloud, mobile, SaaS, and on-premises applications.

Resilience scores

Disruption prediction

Ping Identity has an estimated 11% probability of disruption in the next 6 months.

7 of Ping Identity's 12 vendors monitored for disruptions.

Technology vendors

Services catalogue

10 services in catalogue across 2 categories; runs on 12 sub-vendors.

Insights

Last updated 2026-05-04 · revision 7

12 direct vendors, 193 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Ping Identity exhibits high migration readiness, primarily driven by its exceptionally modern and flexible internal tech stack. The company leverages a multi-cloud strategy (AWS, Azure, GCP), containerization (Kubernetes, Docker), and orchestration (Terraform, Helm), along with microservices-friendly languages (Java, Python, Go) and REST APIs. This cloud-native, agile architecture significantly reduces technical barriers to migration and minimizes vendor lock-in for core infrastructure. Strong revenue growth also suggests the financial capacity to fund complex migration initiatives. However, several factors introduce complexity and prevent a perfect score. The regulatory environment is intricate, with 'Assessment Required' statuses for GDPR, HIPAA, SOC2, and ISO 27001. Any migration would necessitate meticulous planning to ensure continuous compliance with these regulations, especially given the lack of specific audit evidence. Explicit data residency requirements, particularly for global customers (GDPR, industry-specific, sovereign cloud), will add significant overhead to migration planning and execution, requiring careful data placement strategies. While the 'Vendor Relationships' data is ambiguous, the company's multi-cloud and open-source adoption strategy inherently mitigates vendor lock-in risks, enhancing migration flexibility.

Compliance

5 in-scope frameworks identified; showing 3.

HIPAA (source) — Assessment Required

While Ping Identity is not primarily a healthcare company, they provide identity management services to healthcare organizations. If they process Protected Health Information (PHI) as a business associate, HIPAA compliance would be required. The medium risk reflects that non-compliance could result in significant penalties, but applicability depends on specific customer implementations and data handling practices.

ISAE 3000 (source) — Assessment Required

ISAE 3000 provides assurance framework that could be relevant for Ping Identity's service delivery and controls attestation. However, this is typically used in conjunction with other frameworks like SOC2. Low risk as it's not commonly required by customers as a standalone requirement, and non-compliance has minimal direct business impact.

SOC 2 (source) — Assessment Required

As a cloud-based identity management service provider, SOC2 compliance is industry standard and critical for customer trust. Most enterprise customers require SOC2 Type II reports from their identity providers. Non-compliance would significantly impact business competitiveness and customer acquisition. High risk due to business impact rather than regulatory penalties.

Financials

Three-year financials

Financial Resilience Score: 5/10

Ping Identity operated as a publicly traded identity security company (NYSE: PING) until its acquisition by Thales Group in late 2022 for approximately $2.8B. The company demonstrated consistent revenue growth from $231.7M in 2020 to $336.5M in 2022, reflecting strong demand for enterprise identity and access management solutions. However, the company was not consistently profitable on a GAAP basis, relying heavily on subscription-based recurring revenue which provided some revenue predictability but did not translate to operating profitability during its public tenure. The acquisition by Thales removed it from public markets, limiting further financial disclosure. Ping Identity's business model was transitioning from perpetual licenses to SaaS/subscription, which temporarily compressed margins but improved revenue quality and predictability over time. Annual Recurring Revenue (ARR) was a key metric, growing steadily and indicating healthy customer retention. The company served large enterprise and government clients, providing some revenue stability, but faced intense competition from Okta, Microsoft, and others. Post-acquisition by Thales, Ping Identity's standalone financials are no longer publicly disclosed, making current resilience assessment difficult. As a subsidiary of a large French defense and technology conglomerate, it benefits from significant financial backing but loses independent financial transparency. The identity security market remains robust, supporting long-term demand for Ping's products.

Key strengths: Consistent revenue growth trajectory from 2020 to 2022, Recurring subscription/SaaS revenue model improving revenue predictability, Strong enterprise and government customer base, Acquired by Thales Group for ~$2.8B in 2022, providing financial stability, Growing Annual Recurring Revenue (ARR) indicating healthy retention, Identity security market experiencing strong secular demand

Risk factors: Not consistently GAAP profitable during public company period, Intense competition from Okta, Microsoft Azure AD, and others, Post-acquisition financial data no longer publicly disclosed, SaaS transition period compressed margins, Dependence on large enterprise deals creates revenue lumpiness

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report