Raytheon Technologies Corporation

United States · www.rtx.com · 22 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 22 sub-vendors.

Insights

Last updated 2026-08-17 · revision 2

22 direct vendors, 255 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Raytheon Technologies Corporation exhibits a mixed readiness for migration. On the positive side, the company has adopted modern cloud platforms (Microsoft Azure, Amazon Web Services) and containerization technologies (Docker, Kubernetes), indicating a foundational readiness for cloud migration and a modern architectural approach. Proficiency in programming languages like Python and Java also supports re-platforming and re-architecting efforts. However, significant challenges exist due to the presence of large, complex enterprise systems such as SAP ERP, Oracle Database, and Microsoft SQL Server, alongside highly specialized engineering software like Siemens Teamcenter, MATLAB, Ansys, Dassault Systèmes CATIA, and PTC Windchill. These systems likely represent deeply embedded legacy components that would be challenging, costly, and time-consuming to migrate, potentially requiring extensive re-engineering or specialized cloud solutions. A major unknown risk stems from the lack of specified data residency requirements and regulatory environment details; given Raytheon's industry (defense), it is highly probable that stringent regulatory compliance and data residency requirements exist, which would significantly complicate and restrict cloud migration options, especially for sensitive defense data. The 'Vendor Lock-in Risk' is unknown, but the reliance on major enterprise software vendors suggests potential lock-in for specific ecosystems, which could hinder migration flexibility. The absence of data on financial stability also prevents an assessment of the company's ability to fund a large-scale migration.

Compliance

16 in-scope frameworks identified; showing 3.

HIPAA (source) — Partially Compliant

RTX is not a healthcare company, but as a large US employer (185,000+ employees) it sponsors employee health and wellness plans, making it a HIPAA-covered entity or business associate in the context of employee health benefits administration. RTX explicitly publishes a HIPAA Privacy Practices Notice for individuals covered under RTX health and wellness plans. Risk is rated Low because: (1) RTX's HIPAA exposure is limited to employee health plan administration, not core business operations; (2) RTX has publicly acknowledged HIPAA obligations and published a formal HIPAA Privacy Practices Notice; (3) the scope is well-defined and manageable; (4) HIPAA enforcement for employer-sponsored health plans is relatively routine for large corporations of this size. The primary risk would be a data breach involving employee health information.

Evidence: https://www.rtx.com/privacy, https://prd-sc102-cdn.rtx.com/-/media/rtx/r/rtx-hipaa-privacy-notice.pdf

CMMC — Assessment Required

CMMC is a critical compliance requirement for RTX as a major US Department of Defense (DoD) prime contractor. RTX (through Raytheon, Collins Aerospace, and Pratt & Whitney) holds billions of dollars in DoD contracts annually and handles Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). CMMC 2.0 (finalized in December 2024) requires DoD contractors to achieve CMMC Level 2 or Level 3 certification depending on the sensitivity of information handled. Risk is rated High because: (1) RTX's entire DoD contracting business depends on CMMC compliance; (2) CMMC Level 3 (based on NIST SP 800-172) is required for the most sensitive programs; (3) third-party assessment organizations (C3PAOs) must conduct assessments; (4) non-compliance results in contract ineligibility; (5) RTX's supply chain must also achieve appropriate CMMC levels, creating flow-down obligations; (6) CMMC 2.0 enforcement began in 2025 with phased implementation.

Evidence: https://www.rtx.com/our-responsibility/data-security-and-privacy, https://www.rtx.com/suppliers, https://prd-sc102-cdn.rtx.com/-/media/rtx/airshow/who-we-are/our-responsibility/rtx_annual_report_2024_with10k_final.pdf, https://www.acq.osd.mil/cmmc/

NIS2 (source) — Assessment Required

RTX's three business units — Collins Aerospace (avionics, aircraft systems), Pratt & Whitney (aircraft engines), and Raytheon (defense systems, missiles, radars) — operate extensively across EU member states and supply critical infrastructure to EU defense, aviation, and space sectors. NIS2 covers 'Important Entities' in manufacturing (specifically 'manufacture of machinery and equipment,' 'manufacture of motor vehicles,' and critically 'manufacture of other transport equipment' including aerospace/defense) and 'Essential Entities' in digital infrastructure, space, and transport. RTX's EU operations almost certainly exceed the 250-employee/€50M turnover thresholds for large enterprises. Risk is rated High because: (1) NIS2 non-compliance can result in fines up to €10M or 2% of global turnover for Important Entities, and €7M or 1.4% of global turnover for Essential Entities; (2) defense/aerospace supply chains are explicitly in scope; (3) EU member states began enforcing NIS2 from October 2024; (4) RTX's role as a critical defense supplier to NATO and EU governments makes regulatory scrutiny highly likely; (5) cybersecurity incident reporting obligations under NIS2 are stringent (24-hour initial notification). No public NIS2 compliance assessment has been disclosed.

Evidence: https://www.rtx.com/who-we-are/our-businesses, https://www.rtx.com/our-responsibility/data-security-and-privacy, https://www.rtx.com/who-we-are/global-presence, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555

Financials

Three-year financials

Financial Resilience Score: 8/10

RTX Corporation demonstrates strong financial resilience underpinned by a massive $268 billion backlog (approximately 3x annual revenue), diversified revenue mix between commercial (48%) and defense (52%), and robust cash generation of $10.6B operating cash flow and $7.9B free cash flow in 2025. The company holds investment-grade credit ratings (Moody's Baa1/stable, S&P BBB+/stable, both upgraded in 2025) and maintains ample liquidity with a $5.0B undrawn revolving credit facility. Strengths include sole-source or prime contractor positions on marquee programs such as the F135 engine, Patriot, AMRAAM, SPY-6, LTAMDS, GTF, and Tomahawk, plus significant R&D investment (~$7.7B in 2025). Revenue growth has been strong post-2023 Powder Metal charge, with 17% growth in 2024 and 10% in 2025, and operating margins have expanded from 5.2% to 10.5% over three years. Offsetting these strengths are elevated debt of $37.9B (36% debt-to-cap), ongoing costs from the Pratt & Whitney Powder Metal Matter (an estimated $0.7B additional cash impact in 2026), and significant legal/compliance overhang including two DOJ Deferred Prosecution Agreements, an SEC Administrative Order, and a State Department Consent Agreement. Customer concentration is meaningful with the U.S. government at 38% (46% including FMS) and Airbus at ~14% of total sales. Multiple DCMA claims exceeding $3B against Pratt & Whitney and an ongoing SEC investigation into powder metal disclosures represent additional tail risks.

Key strengths: $268B backlog (~3x annual revenue) providing strong revenue visibility, Diversified 48% commercial / 52% defense revenue mix, Strong cash generation: $10.6B operating cash flow, $7.9B free cash flow in 2025, Investment-grade credit ratings (Moody's Baa1/stable, S&P BBB+/stable), $5.0B undrawn revolving credit facility plus $0.6B other short-term facilities, Sole-source/prime contractor positions on major defense programs, ~$7.7B combined R&D spend supporting long-term competitiveness, Operating margin expansion from 5.2% (2023) to 10.5% (2025)

Risk factors: Pratt & Whitney Powder Metal Matter with $0.7B accrued liability and ~$0.7B additional 2026 cash impact, Elevated total debt of $37.9B (36% debt-to-capitalization), Two DOJ Deferred Prosecution Agreements, SEC Administrative Order, and State Department Consent Agreement, U.S. government concentration at 38% of sales (46% including FMS), Airbus concentration at ~14% of total sales; 29% of Pratt & Whitney segment, DCMA claims against Pratt & Whitney totaling >$3B, Ongoing SEC investigation regarding powder metal disclosures, Supply chain exposure to tariffs and foreign sourcing of critical materials (cobalt, tantalum, titanium), Fixed-price development contract risk (e.g., 2024 $0.6B Raytheon contract termination), Independent compliance monitor to be installed by end of Q1 2026

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report