PrestaShop SA
France · owned by Independent (France) · www.prestashop.com · 23 vendors
PrestaShop is a French open-source e-commerce platform that enables businesses to create and manage online stores. It provides merchants with tools to customize their storefronts, manage products and payments, and scale their online retail operations. The platform serves hundreds of thousands of merchants worldwide and offers both a free open-source solution and cloud-hosted options.
Resilience scores
- Digital Sovereignty: 26
- Digital Resilience: 8
- Financial Resilience: 6
Disruption prediction
PrestaShop SA has an estimated 11% probability of disruption in the next 6 months.
14 of PrestaShop SA's 23 vendors monitored for disruptions.
Technology vendors
- AB Tasty — Technology — France
- Anthropic, PBC — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 20 more
Services catalogue
2 services in catalogue across 1 category; runs on 23 sub-vendors.
- eCommerce Platform
- PrestaShop
Insights
Last updated 2026-07-30 · revision 2
23 direct vendors, 280 subvendors
Direct vendors by controlling owner country (sample)
- Spain: 1
- France: 2
- Australia: 1
Subvendors by controlling owner country (sample)
- Germany: 8
- Japan: 2
- Czech Republic: 1
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
PrestaShop exhibits moderate migration readiness. Its use of a modern Symfony 6.4 framework and an API-driven architecture (API Platform, REST API) provides a solid foundation for potential cloud migration, allowing for modularity and easier integration. The financial stability provided by the MBE Worldwide acquisition would likely support funding a significant migration effort. However, several factors present challenges. There is no explicit mention of advanced cloud-native practices such as containerization (e.g., Docker, Kubernetes) or a microservices architecture for its core platform, which would typically indicate higher readiness for seamless cloud adoption. A major constraint is the strict regulatory environment, including GDPR and NIS2 compliance, coupled with primary data residency requirements within the European Union. Any migration strategy would need to meticulously adhere to these, potentially limiting the choice of cloud providers and regions and increasing complexity. Furthermore, while vendor geographic diversity is present, the "Vendor Lock-in Risk" is unknown. The company relies on specific vendors for key services (e.g., Gandi for hosted offering, PayPal for payments, Klaviyo for marketing automation), and with 20 total services identified, managing these existing vendor relationships and potential lock-in during a migration would be a critical consideration. The open-source nature of PrestaShop Classic offers flexibility for its users, but PrestaShop's own internal systems and hosted offerings would face these migration challenges.
Compliance
8 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
ISO 27001 is highly relevant for PrestaShop as a technology company providing SaaS e-commerce services to 250,000+ merchants globally, processing significant volumes of merchant and customer data. The risk is Medium because: (1) without ISO 27001 certification, PrestaShop cannot formally demonstrate to enterprise customers, partners, and regulators that its information security management system meets international standards; (2) ISO 27001 certification would also support NIS2 compliance (Article 24 of NIS2 references European and international standards); (3) the absence of certification increases reputational and contractual risk with enterprise clients; (4) France's ANSSI actively promotes ISO 27001 as a baseline for NIS2 compliance. No ISO 27001 certificate was found in public documentation.
Evidence: https://www.prestashop.com/security-charter/, https://www.prestashop.com/privacy-policy/
French Loi Informatique et Libertés — Partially Compliant
As a French company, PrestaShop SA is subject to the French Data Protection Act ('Loi Informatique et Libertés' of 6 January 1978, as amended by Loi n°2018-493 to align with GDPR). The Privacy Policy explicitly references this law alongside GDPR. The CNIL is the supervisory authority. Risk is Medium because CNIL has been increasingly active in enforcement actions against French technology companies, and the combination of GDPR and French national law creates layered obligations (e.g., specific rules on employee data, direct marketing under Article L.34-5 of the CPCE). PrestaShop's use of GDPR compliance software (DATA LEGAL DRIVE) and documented rights procedures indicate active compliance efforts.
Evidence: https://www.prestashop.com/privacy-policy/, https://www.cnil.fr
NIS2 (source) — Assessment Required
PrestaShop SA is a French-headquartered technology company providing an e-commerce platform (SaaS hosted offering and open-source software) to 250,000+ merchants globally. NIS2 came into force in France via transposition into national law (Loi n°2023-703 and ANSSI implementing measures). The 'digital providers' category under NIS2 Annex II (Important Entities) includes 'online marketplaces', 'online search engines', and 'cloud computing service providers'. PrestaShop's hosted/SaaS offering could qualify as a 'cloud computing service' or 'online marketplace platform provider' under NIS2 scope. The company's scale (250,000+ merchants, global operations, significant revenue) strongly suggests it exceeds the medium enterprise threshold (50+ employees, €10M+ turnover). Risk is Medium because: (1) the exact NIS2 classification (Important Entity vs. Essential Entity) requires formal assessment by ANSSI (France's NIS2 competent authority); (2) non-compliance with NIS2 in France carries fines up to €10M or 2% of global turnover for Important Entities; (3) NIS2 obligations include incident reporting (24h initial notification to ANSSI), security measures, supply chain security, and vulnerability disclosure — areas where PrestaShop has partial evidence of compliance (security charter, CVE program) but no formal NIS2 registration is publicly confirmed.
Evidence: https://www.prestashop.com/security-charter/, https://www.prestashop.com/privacy-policy/
Financials
Three-year financials
- 2023:
- 2022:
- 2021:
Financial Resilience Score: 6/10
PrestaShop demonstrates solid qualitative resilience through its strong brand position as the leading open-source e-commerce platform in Europe and Latin America, with approximately 250,000 active merchant stores generating over €22 billion in merchant GMV in 2024. The company benefits from being a subsidiary of MBE Worldwide (backed by Oakley Capital), providing balance-sheet support and cross-selling opportunities across logistics and e-commerce services in 50+ countries. Its diversified monetization model, spanning open-source core, SaaS/Hosted offerings, Addons marketplace commissions, and payment revenue share (PrestaShop Checkout with PayPal, Stripe, Klarna, Alma, Airwallex), provides recurring and transaction-based revenue streams that are more resilient than one-shot license sales. However, the resilience score is tempered by significant competitive pressure from Shopify (SaaS-first) and WooCommerce (open-source competitor), requiring costly investment in SaaS transition. Merchant concentration in Southern Europe and Latin America—regions with slower e-commerce growth than the US/Northern Europe—combined with post-COVID e-commerce normalization and EU SME retail softness, could dampen transaction revenue growth. Multiple CEO/Managing Director changes between 2023 and 2026 signal an ongoing strategic reset, and the free Classic version poses cannibalization risk. As a private subsidiary with thin public disclosure, no bond, and no rating, external stakeholders have limited visibility into financial health.
Key strengths: Leading open-source e-commerce platform in Europe and Latin America with ~250,000 active merchant stores, Merchant GMV of over €22 billion in 2024, Backing by MBE Worldwide (Oakley Capital-owned), providing balance-sheet support and cross-selling opportunities, Diversified monetization: SaaS subscriptions, Addons marketplace commissions, payment revenue share, Strong community moat with 1M+ community members, 250+ Experts, 150+ partners, Recurring and transaction-based revenue streams from payments and SaaS
Risk factors: Intense competitive pressure from Shopify (SaaS-first) and WooCommerce (open-source), Merchant concentration in Southern Europe and Latin America—slower-growth e-commerce regions, Post-COVID e-commerce normalization and EU SME retail macro softness, Multiple CEO/Managing Director changes between 2023 and 2026 indicate strategic instability, Open-source Classic version cannibalizes SaaS monetization potential, Private ownership with thin public disclosure; no IR reporting, bond, or credit rating
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.