Renault

France · www.renault.com · 28 vendors

Renault S.A. is a French multinational automobile manufacturer that designs, manufactures, and sells a range of vehicles, including passenger cars, light commercial vehicles, and electric vehicles. The company operates under brands such as Renault, Dacia, and Alpine, and is a major player in electric and hydrogen mobility.

Resilience scores

Disruption prediction

Renault has an estimated 10% probability of disruption in the next 6 months.

16 of Renault's 28 vendors monitored for disruptions.

Technology vendors

Services catalogue

3 services in catalogue across 3 categories; runs on 28 sub-vendors.

Insights

Last updated 2026-08-14 · revision 1

28 direct vendors, 316 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Renault exhibits a medium level of migration readiness, with several key strengths and notable challenges. The company's adoption of 'Cloud Computing' across engineering and operations is a significant positive indicator, demonstrating a foundational step towards modern infrastructure. Strategic initiatives like the 'Industrial Metaverse', AI integration, and the 'Digital Continuity Platform' suggest a proactive approach to digital transformation, which aligns well with migration to more agile, cloud-native environments. The 'Software République Ecosystem' with major tech partners like Microsoft and Google also provides access to expertise and tools that can facilitate complex migrations. However, significant challenges and unknowns temper this readiness. As a large manufacturing entity, Renault likely relies on substantial legacy systems, explicitly mentioning 'SAP (ERP for manufacturing and supply chain operations)' and 'PLM / CAD Software'. Migrating these core, often monolithic, systems can be highly complex, time-consuming, and costly. Critical information regarding 'Data Residency Requirements' and the 'Regulatory Environment' is not specified, which are essential for planning a compliant and legally sound migration strategy, especially for a company operating in 24 countries. The 'Vendor Lock-in Risk' is 'Unknown', which is a major concern. While 'Total Services: 22' from vendors across 6 countries indicates a diverse set of external dependencies, without knowing the number of distinct vendors or the nature of contractual agreements, the potential for vendor lock-in and the complexity of disentangling these relationships during migration remain high. The absence of data on financial stability also means the ability to fund a large-scale migration effort cannot be fully assessed. Therefore, while there's a clear move towards modernization, the presence of legacy systems and critical data gaps position Renault in the medium readiness category.

Compliance

13 in-scope frameworks identified; showing 3.

EU Cybersecurity Act — Compliant

UNECE WP.29 UN Regulation No. 155 (Cyber Security Management System — CSMS) and UN Regulation No. 156 (Software Update Management System — SUMS) are mandatory for all new vehicle type approvals in the EU from July 2022 (new types) and July 2024 (all new vehicles). As a major EU automotive OEM, Renault must comply to sell vehicles in the EU. The risk level is High because: (1) non-compliance results in inability to obtain type approval for new vehicles — a business-critical consequence; (2) the regulation covers the entire vehicle lifecycle including connected services; (3) Renault's software-defined vehicle strategy (Ampere) significantly expands the cybersecurity attack surface; (4) type approval authorities (DREAL in France, RDW in Netherlands) actively enforce these requirements.

Evidence: https://unece.org/transport/vehicle-regulations/un-regulation-no155-cyber-security-and-cyber-security-management, https://www.renaultgroup.com/, https://ampere.cars/

ISO 27001 (source) — Assessment Required

ISO 27001 is the international standard for Information Security Management Systems (ISMS) and is highly relevant to Renault Group given its scale, digital transformation, and automotive industry context. The risk level is Medium because: (1) ISO 27001 is not legally mandated but is strongly expected in the automotive supply chain and by OEM partners; (2) TISAX (Trusted Information Security Assessment Exchange), which is built on ISO 27001 principles, is the de facto standard for automotive manufacturers and suppliers in Europe; (3) Renault's connected vehicle platform, manufacturing OT systems, and financial services arm all require robust ISMS; (4) failure to maintain ISO 27001 or TISAX certification could impact supplier relationships and tender eligibility.

Evidence: https://www.enx.com/tisax/, https://www.renaultgroup.com/securite-et-confidentialite/, https://assets.renaultgroup.com/uploads/2026/03/DEU_2025_comp_202603191340.pdf

NIS2 (source) — Assessment Required

NIS2 (EU Directive 2022/2555, transposed into French law via Loi n°2023-703 and ANSSI implementing measures) is highly likely applicable to Renault Group as an 'Important Entity' under the Manufacturing sector category (Annex II of NIS2 covers manufacture of motor vehicles, trailers and semi-trailers — NACE C29). Renault Group vastly exceeds the size thresholds (large enterprise: 250+ employees and €50M+ turnover). The risk level is High because: (1) NIS2 imposes mandatory cybersecurity risk management measures, incident reporting (within 24h/72h), supply chain security obligations, and management body accountability; (2) non-compliance penalties can reach €7M or 1.4% of global annual turnover for Important Entities; (3) Renault's highly connected manufacturing operations, software-defined vehicles (Ampere), and extensive IT/OT infrastructure in French factories create significant attack surface; (4) ANSSI (France's cybersecurity agency) is actively enforcing NIS2 transposition; (5) Renault was subject to a significant cyberattack (WannaCry, 2017) demonstrating real-world cyber risk in automotive manufacturing.

Evidence: https://www.renaultgroup.com/, https://assets.renaultgroup.com/uploads/2026/03/DEU_2025_comp_202603191340.pdf, https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000047866733, https://www.anssi.gouv.fr/actualite/nis2-la-directive-europeenne-sur-la-cybersecurite/

Financials

Three-year financials

Financial Resilience Score: 8/10

Renault Group demonstrates strong financial resilience with a robust balance sheet, highlighted by a positive automotive net financial position of €7.4 billion at end-2025—a rare achievement among European legacy automakers. The Group has successfully executed its Renaulution transformation plan, expanding operating margins from 3-4% in 2021 to 6.3% in 2025, well above the 20-year average of 3.9%. Revenue has grown consistently from €46.2B in 2021 to €57.9B in 2025 (CAGR ~5.8%), driven by a value-over-volume strategy with retail mix 17 points above market average and residual values 5-12 points above competitors. The company benefits from a diversified brand portfolio (Renault, Dacia, Alpine) with strong product momentum—32 launches in 5 years, multiple 'Car of the Year' awards, and Dacia Sandero as Europe's best-selling car. Electrification is progressing well, with 60.1% of Renault-brand European sales being electrified in 2025. However, resilience is tempered by significant Nissan exposure (€2.3B associate loss and €9.3B non-cash reclassification loss in 2025), intense Chinese EV competition, heavy capex requirements for EV/SDV transition, and a cautious 2026 margin guidance of 5.5% (below 2025's 6.3%). The recent CEO change adds execution risk to the new futuREady plan.

Key strengths: Automotive net cash position of +€7.4B at end-2025, Operating margin of 6.3% in 2025, above 20-year average of 3.9%, Automotive free cash flow of €1.5B in 2025, Value-over-volume strategy with premium residual values, 60.1% electrified mix on Renault brand in Europe, Strong product pipeline: 32 launches in 5 years, Diversified brand portfolio (Renault, Dacia, Alpine, Mobilize), Dividend increased/maintained at €2.20 per share, ESG leadership: Sustainalytics Low Risk, EcoVadis Gold

Risk factors: Nissan exposure caused €9.3B non-cash reclassification loss in 2025, Chinese EV competition pressuring European margins, Heavy CAPEX/R&D requirements (€1.5B/year for EV 2026-2028), EU regulatory burden (CO₂, ELV Act, CRMA, CSRD), Geopolitical/supply-chain risk on critical minerals, CEO transition (July 2025) with execution risk on futuREady plan, 2026 margin guidance (5.5%) below 2025 outcome (6.3%), Net income drop from €2.20B (2023) to €0.72B (2025)

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report