Semtech

United States · www.semtech.com · 21 vendors

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 1 category; runs on 21 sub-vendors.

Insights

Last updated 2026-09-13 · revision 2

21 direct vendors, 246 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Semtech's migration readiness is assessed as low to medium, primarily due to a highly complex and partially unaddressed regulatory landscape coupled with explicit, demanding data residency requirements. While the company utilizes modern SaaS solutions for its internal tech stack (Workday, Salesforce, HubSpot) and operates its own cloud platforms (LoRa Cloud, AirVantage, Octave), suggesting some cloud adoption and internal capabilities, these do not fully offset the significant compliance burden. The regulatory environment presents substantial migration challenges: GDPR, NIS2, SOC 2, EAR/ITAR, and SEC Cybersecurity Disclosure Rules are all either partially compliant or require further assessment, with several carrying medium to high risk. Any migration effort would need to meticulously address these complex requirements, particularly for data handling and system architecture. Explicit data residency requirements are a major impediment, with strict localization mandates for China, specific transfer mechanisms needed for EU/EEA and UK data, and evolving privacy laws in Canada (Quebec Law 25) and various US states. These necessitate careful planning and potentially costly architectural changes to ensure compliance during and after migration. Vendor lock-in, while not explicitly quantified, is a moderate concern. The reliance on major SaaS providers like Salesforce (CRM) and Workday (HCM) for core business functions implies significant dependencies that would complicate any migration away from these platforms. The financial stability to fund a large-scale migration is also unknown. Overall, while Semtech has some modern technology components, the sheer complexity of its regulatory and data residency obligations, combined with moderate vendor lock-in, significantly lowers its readiness for substantial digital migration initiatives.

Compliance

10 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

Semtech has confirmed EU operations (France, UK — noting UK is post-Brexit but France is firmly EU). NIS2 applies to entities in the EU that meet size thresholds (50+ employees or €10M+ turnover) and operate in listed sectors. Semtech's revenue exceeds €10M globally (Nasdaq-listed, ~$700M+ annual revenue), and its French subsidiary (Grenoble/Meylan) almost certainly exceeds the size threshold. The key question is sector classification: Semtech is a semiconductor manufacturer and IoT/cloud connectivity provider. Under NIS2, 'digital infrastructure' and 'ICT service management' are Essential Entity categories, while 'manufacturing' (of electronics/semiconductors) and 'digital providers' are Important Entity categories. Semtech's LoRa Cloud Services, AirVantage managed connectivity, and Octave IoT platform could qualify as digital infrastructure or ICT service management. The risk is Medium because while the sector match is plausible, formal classification by French/EU authorities has not been publicly confirmed, and Semtech's primary business is hardware manufacturing rather than operating critical infrastructure directly.

Evidence: https://www.semtech.com/company/locations/north-america, https://www.semtech.com/uploads/quality/ISO-27001-certificate.pdf, https://www.semtech.com/uploads/quality/ISO-22301-Certificate-BCMS-807806-001.pdf, https://www.semtech.com/uploads/quality/QMS_SunCert_134L_Semtech_France.pdf

RoHS — Compliant

Semtech explicitly maintains a 'Search Pb(Lead)-Free/RoHS-Green' database on its website, demonstrating active RoHS compliance management for its semiconductor products sold in the EU. The company also holds Sony Green Partner certificates (Camarillo and Colorado Springs), which require RoHS compliance. As a semiconductor manufacturer selling into the EU market, RoHS and REACH compliance are mandatory. The risk is Low given the active compliance infrastructure and Green Partner certifications.

Evidence: https://www.semtech.com/quality/certifications, https://www.semtech.com/quality/search-pb-lead-free-rohs-green, https://www.semtech.com/uploads/quality/ISO_14001_-_4620_Semtech_Corp_(Camarillo)_EMS_Recert_2026-2029.pdf

CPRA — Compliant

Semtech is headquartered in Camarillo, California, and explicitly addresses CCPA compliance in its privacy policy, including disclosure of data categories collected, opt-out rights for sale/sharing of personal information, Shine the Light law compliance, and a dedicated data request portal. The company provides a 'Do Not Sell or Share My Personal Information' link and a toll-free number for California residents. This demonstrates active CCPA/CPRA compliance management. The risk is Low because Semtech's primary business is B2B semiconductor sales rather than consumer data monetization, limiting CCPA exposure.

Evidence: https://www.semtech.com/legal, https://info.semtech.com/data-request

Financials

Three-year financials

Financial Resilience Score: 6/10

Semtech has shown a meaningful recovery in financial resilience over the past two years following the disastrous FY2024 that included ~$887M in goodwill and intangible impairments tied to the Sierra Wireless acquisition. Revenue has re-accelerated sharply to $1.05B in FY2026 (+15.5% YoY), gross margins expanded from 34.1% to 51.6%, and operating cash flow rebounded to $181.2M from a negative $93.9M two years earlier. A $640.7M secondary equity offering in December 2024 repaired a stockholders' equity deficit, and the company fully repaid its Term Loan in FY2026, leaving no drawn revolver and $451.6M of undrawn capacity. However, resilience is tempered by continued impairments (an additional $84.8M goodwill charge in FY2026), a still-negative bottom line ($40.4M net loss), and heavy convertible notes overhang ($100.5M 2027 Notes and $402.5M 2030 Notes). Structural risks include customer concentration (two customers each 11-14% of sales), extreme geographic concentration in China (47% of sales), heavy distributor dependence (74% of sales), and a planned divestiture of the cellular module business. Cash position is healthy at $195.2M and the AI/data-center demand tailwind is real, but the company remains in a turnaround phase rather than a position of durable financial strength.

Key strengths: Revenue crossed $1B threshold in FY2026 with +15.5% YoY growth, Gross margin expansion from 34.1% to 51.6% over three years, Operating cash flow rebounded to $181.2M from negative $93.9M, Full repayment of Term Loan in FY2026, $640.7M secondary equity offering repaired balance sheet, $195.2M cash and $451.6M undrawn revolver capacity, Strong AI/data-center demand tailwind driving Infrastructure segment, Fab-lite manufacturing model provides capital flexibility

Risk factors: Customer concentration: two customers each 11-14% of net sales, China geographic concentration at 47% of FY2026 sales, 74% of sales through independent distributors with cancellable contracts, Convertible notes overhang: $100.5M 2027 Notes and $402.5M 2030 Notes, 2027 Notes became convertible at holders' option in January 2026, Recurring impairments (~$975M cumulative over three years), Planned divestiture of cellular module business creates execution risk, Cyclical semiconductor industry with rapid ASP declines, Supply concentration in Asian foundries (Taiwan, China, Japan, Israel, Vietnam), Prior material weaknesses in internal controls (remediated but must be maintained), US-China trade tensions, tariffs, and export controls

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report