Rocky Enterprise Software Foundation (RESF)
United States · rockylinux.org · 18 vendors
The Rocky Enterprise Software Foundation (RESF) is an organization that manages and develops open-source projects, primarily the Rocky Linux operating system. It aims to provide a stable foundation of enterprise-grade open-source software that is freely available and community-controlled.
Resilience scores
- Digital Sovereignty: 83
- Digital Resilience: 7
- Financial Resilience: 5
Disruption prediction
Rocky Enterprise Software Foundation (RESF) has an estimated 27% probability of disruption in the next 6 months.
7 of Rocky Enterprise Software Foundation (RESF)'s 18 vendors monitored for disruptions.
Technology vendors
- Civilized Discourse Construction Kit, Inc. — Technology — United States
- IST Group AB — Other — Sweden
- Vultr — Technology — United States
- and 16 more
Services catalogue
1 service in catalogue across 1 category; runs on 18 sub-vendors.
- Linux operating system
Insights
Last updated 2026-07-30 · revision 1
18 direct vendors, 213 subvendors
Direct vendors by controlling owner country (sample)
- United States: 15
- Sweden: 2
- Canada: 1
Subvendors by controlling owner country (sample)
- Finland: 3
- Hong Kong: 1
- Germany: 5
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
RESF exhibits exceptionally high migration readiness, scoring 85. **Strengths:** * **Advanced Cloud-Native Architecture:** RESF's internal tech stack is already highly cloud-native, containerized (Docker, Kubernetes), and microservices-oriented (Istio, Temporal). This architecture is inherently designed for portability and efficient deployment across various cloud environments. * **Multi-Cloud Expertise and Infrastructure-as-Code (IaC):** The company actively uses AWS, Google Cloud, and Microsoft Azure, demonstrating existing multi-cloud capabilities. Coupled with extensive use of IaC tools like Terraform and Ansible, and robust CI/CD pipelines (GitLab CI, GitHub Actions), RESF can rapidly provision, manage, and migrate infrastructure and applications with high efficiency and minimal manual effort. * **Minimal Vendor Lock-in (Contractual):** The explicit statement "Total Vendors: 0" is a major advantage for migration readiness. It suggests a lack of complex, binding vendor contracts that typically create significant hurdles and costs during migration efforts. This provides RESF with maximum flexibility to switch platforms, adopt new technologies, or optimize existing deployments without contractual penalties. * **Open Source Focus:** The nature of RESF's products (Rocky Linux, Peridot) and its reliance on open-source tools (Koji, OpenQA) aligns with a philosophy of avoiding proprietary lock-in, further enhancing migration flexibility. **Weaknesses/Unknowns:** * **Financial Capacity:** The absence of financial data means the capacity to fund large-scale or complex future migrations is unknown. However, given their current highly optimized and automated environment, the cost of incremental migrations is likely lower. * **Regulatory and Data Residency:** No specific regulatory or data residency requirements are provided. Should such requirements be stringent, they could introduce additional complexity and cost to future migration planning, particularly concerning data movement and compliance across different regions or cloud providers.
Compliance
7 in-scope frameworks identified; showing 3.
US Export Controls — Assessment Required
Rocky Linux includes cryptographic software (OpenSSL, GnuTLS, kernel crypto subsystem, etc.) that is subject to US Export Administration Regulations (EAR) under the Bureau of Industry and Security (BIS). Open-source cryptographic software has specific EAR notification requirements (15 CFR § 742.15(b)) — exporters must notify BIS and NIST when making publicly available encryption source code. RESF distributes Rocky Linux globally including to countries that may be subject to US export restrictions. The risk is Medium because open-source software generally benefits from EAR License Exception TSU, but formal compliance documentation is not publicly available.
Evidence: https://rockylinux.org/, https://rockylinux.org/legal/licensing
GDPR (source) — Partially Compliant
RESF is a US-based non-profit open-source foundation headquartered in Albany, CA, but it explicitly collects personal data from a global user base, including EU/EEA residents (IP addresses, email addresses, geolocation data, browser user agents, account information, and usage data via YUM/DNF package manager telemetry). The privacy policy, last updated December 9, 2021, is over three years old and does not explicitly reference GDPR, lawful bases for processing under Article 6, data subject rights under GDPR (Articles 15–22), Data Protection Officer (DPO) appointment, or cross-border transfer mechanisms (e.g., Standard Contractual Clauses) for data transferred from the EU to the US via third-party processors such as AWS, GitHub, Google Workspace, and Vercel. The risk is Medium rather than High because RESF is a small non-profit community foundation with no commercial revenue model, limiting the scale of enforcement exposure, and it does not sell personal data. However, the absence of GDPR-specific disclosures and the outdated privacy policy represent a genuine compliance gap.
Evidence: https://rockylinux.org/legal/privacy, https://rockylinux.org/
Open Source License Compliance — Compliant
RESF explicitly publishes its licensing terms under BSD 3-Clause for RESF-developed components and CC BY-SA 4.0 for website content. Rocky Linux rebuilds from RHEL source RPMs, which are governed by various open-source licenses (GPL, LGPL, MIT, Apache, etc.). RESF provides tooling (rpm -qa) for users to enumerate component licenses. This is a well-managed area with clear public documentation. The risk is Low because RESF's open-source licensing approach is transparent and well-documented.
Evidence: https://rockylinux.org/legal/licensing, https://digitalpublicgoods.net/
Financials
Three-year financials
- 2025:
- 2024:
- 2023:
Financial Resilience Score: 5/10
The Rocky Enterprise Software Foundation (RESF) is a Delaware Public Benefit Corporation that does not publish audited financial statements, IRS Form 990, or SEC filings. As a result, quantitative financial resilience cannot be independently verified. The organization is funded primarily through corporate sponsorships and in-kind contributions rather than product revenue, and it operates with a lean paid staff supplemented by volunteer contributors and seconded engineers from sponsor companies (notably CIQ). Strengths include a diverse sponsor base spanning hyperscalers (AWS, Google Cloud), silicon vendors (ARM, Supermicro), and enterprise software firms, alongside a low fixed cost base due to volunteer contributions and donated infrastructure. Cost-optimization initiatives such as the 2026 Infrastructure v2 program and self-hosting at Fibertown in Texas further support sustainability. The Delaware PBC form and Digital Public Good status insulate the project from single-vendor capture. However, meaningful risks exist: financial opacity, likely sponsor concentration around CIQ, upstream dependency on Red Hat/RHEL source availability, key-person risk highlighted by the June 2026 departure of co-founder Louis Abel, and the absence of any revenue-generating product to offset sponsorship shortfalls. Overall the entity appears operationally stable but its financial resilience remains unverifiable from public sources.
Key strengths: Diverse corporate sponsor base including AWS, Google Cloud, ARM, Microsoft/VMware, Rakuten Symphony, NAVER Cloud, Equinix, Fastly, and Supermicro, Low fixed cost base driven by volunteer contributors and donated cloud/hardware infrastructure, Strong commercial ecosystem partner CIQ providing indirect financial and engineering support, Delaware Public Benefit Corporation structure and Digital Public Good status prevent single-vendor capture, Infrastructure v2 cost-optimization initiative and move to self-hosted Fibertown (Texas) infrastructure, Participation in OpenELA (with SUSE and Oracle) securing long-term RHEL source availability
Risk factors: No published audited financials, IRS Form 990, or SEC filings — full financial opacity, Likely sponsor concentration risk with CIQ believed to be the largest single contributor, Upstream dependency on Red Hat/IBM RHEL source access policies, Key-person risk highlighted by June 2026 departure of co-founder Louis Abel, No revenue-generating product; shortfalls must be closed by new sponsorship, Volunteer contributor onboarding gaps identified in 2026 community survey
Revenue by product/service
- Rocky Linux: 100%
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.