SES S.A.

Luxembourg · www.ses.com · 19 vendors

SES S.A. is a Luxembourgish communications satellite operator that provides video and data connectivity worldwide. The company serves broadcasters, content and internet service providers, mobile and fixed network operators, governments, and institutions. It operates a global fleet of satellites in geostationary and medium Earth orbits.

Resilience scores

Technology vendors

Services catalogue

6 services in catalogue across 2 categories; runs on 19 sub-vendors.

Insights

Last updated 2026-08-12 · revision 7

19 direct vendors, 288 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

SES S.A. exhibits a strong foundation for migration readiness, largely due to its advanced and cloud-centric technology stack. The company has extensively adopted major cloud platforms (Microsoft Azure, AWS) and implemented private, end-to-end satellite-based connectivity to these platforms (Azure ExpressRoute, AWS Direct Connect), indicating a mature multi-cloud strategy. The use of Software-Defined Networking (SDN) and a cloud-enabled network architecture provides significant flexibility and agility crucial for migration. Furthermore, SES's strong projected financial growth provides the necessary capital to fund complex migration initiatives. While the 'Total Vendors: 0' data point is noted as an anomaly, the 'Vendor Geographic Diversity' across 8 unique countries suggests a potentially diverse vendor ecosystem, which can reduce lock-in to a single vendor or region. However, migration readiness is significantly challenged by a highly complex and multi-jurisdictional data residency landscape. Obligations under GDPR (EU/EEA), US government contracts (FedRAMP, DFARS, CMMC), and specific national laws in China (DSL/PIPL), India (DPDPA), Brazil (LGPD), and UAE will necessitate highly segmented, localized, and potentially hybrid migration strategies. This complexity will increase costs, timelines, and architectural constraints. Additionally, maintaining stringent regulatory compliance (e.g., NIS2, ITAR/EAR, GDPR, SOC 2, ISO 27001) throughout any migration process will require detailed impact assessments, potentially re-certification for new environments, and careful adherence to security and export control requirements, adding substantial overhead and complexity to any large-scale migration effort. The 'Unknown' vendor lock-in risk also presents an area of uncertainty that could impact migration flexibility.

Compliance

13 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

SES provides managed connectivity services, cloud-integrated satellite solutions (Azure ExpressRoute, AWS Direct Connect integrations), and managed services to enterprise and government customers globally. These service types commonly trigger SOC 2 audit requirements from enterprise and government customers as part of vendor due diligence. Risk is Medium because: (1) SES's government and enterprise customers (especially US-based) frequently require SOC 2 Type II reports as a condition of contract; (2) SES Space & Defense (US subsidiary) likely faces SOC 2 expectations from US government clients; (3) Absence of a publicly disclosed SOC 2 report may create friction in enterprise sales cycles. However, risk is not High because SES's primary regulatory framework is EU-based (ISO 27001, NIS2, GDPR) and SOC 2 is a US-centric voluntary framework.

Evidence: https://www.ses.com/network-and-technology/technology-enablers/cloud, https://www.ses.com/network-and-technology/technology-enablers/azure-expressroute, https://www.ses.com/network-and-technology/technology-enablers/aws-direct-connect, https://www.ses.com/solutions/government/managed-services

NIS2 (source) — Assessment Required

SES S.A. is highly likely to qualify as an Essential Entity under NIS2 on multiple grounds: (1) It is explicitly classified under the 'Space' sector, which is listed as an Essential Entity sector in Annex I of NIS2 Directive (EU) 2022/2555; (2) It provides digital infrastructure (satellite communications, ground networks, teleports) which also falls under Essential Entity classification; (3) It serves government clients including defence and institutional programs (GovSatCom, IRIS²), further elevating its criticality; (4) With 4,000+ employees and revenues well exceeding €10M, it far surpasses NIS2 size thresholds. Risk is rated High because: non-compliance with NIS2 can result in fines up to €10M or 2% of global annual turnover for Essential Entities; Luxembourg has transposed NIS2 into national law; satellite operators providing critical communications infrastructure are a primary target of NIS2 enforcement; and SES's role in IRIS² (EU sovereign connectivity) makes it a strategically critical entity. The 'Assessment Required' status reflects that while applicability is near-certain, the specific registration, incident reporting, and security measure implementation status has not been publicly confirmed by SES.

Evidence: https://www.ses.com/company/environmental-social-and-governance/governance, https://www.ses.com/network-and-technology/technology-enablers/security/cyber-security, https://www.ses.com/solutions/government/institutional-programs/govsatcom, https://www.ses.com/news/press-release/ses-advances-nextgeneration-meo-strategy-following-successful-completion-of

ISAE 3000 (source) — Assessment Required

ISAE 3000 is relevant to SES primarily in the context of ESG reporting assurance. SES publishes an annual ESG Report and is subject to EU Taxonomy disclosure obligations (as evidenced by its FY2025 EU Taxonomy Restatement press release). Large EU-listed companies subject to CSRD (Corporate Sustainability Reporting Directive) are required to obtain limited assurance (and eventually reasonable assurance) on sustainability disclosures, typically performed under ISAE 3000 or equivalent standards. SES is listed on Luxembourg and Paris Euronext stock exchanges, making it subject to CSRD. Risk is Low because ISAE 3000 non-compliance in this context is an emerging requirement (CSRD phased implementation) and does not carry the same immediate enforcement risk as GDPR or NIS2.

Evidence: https://www.ses.com/company/environmental-social-and-governance/esg-reporting, https://www.ses.com/company/environmental-social-and-governance/governance/auditors, https://www.ses.com/news/press-release/ses-publishes-fy2025-eu-taxonomy-restatement, https://www.ses.com/company/environmental-social-and-governance/governance/disclosure-obligations

Financials

Three-year financials

Financial Resilience Score: 6/10

SES demonstrates moderate financial resilience, supported by a large contracted backlog of EUR 6.6 billion providing multi-year revenue visibility, an investment-grade credit profile, and diversified revenue streams across Media, Government, Fixed & Maritime, and Aviation. The company maintains a strong strategic position as the world's largest combined GEO/MEO fleet operator with approximately 120 satellites following the Intelsat acquisition, and has a growing defensible government revenue pillar including IRIS², GovSat-2, and U.S. PTS-G contracts. However, resilience has been materially weakened by the July 2025 Intelsat acquisition. Net leverage jumped from 1.1x in 2024 to 3.9x in 2025, cash reserves dropped from EUR 3,521M to EUR 1,075M, and equity attributable to parent fell 23% in one year. The company also reported a net loss of EUR 95M in 2025, following a EUR 905M loss in 2023 driven by a EUR 3.7B impairment. Structural decline in Media/Video revenue, weakness in Fixed Data, competitive pressure from LEO constellations like Starlink and Kuiper, and heavy ongoing CapEx (guided ~EUR 700M for 2026) further constrain resilience. Deleveraging will depend on successful Intelsat synergy delivery.

Key strengths: EUR 6.6B contracted backlog providing multi-year revenue visibility, EUR 1.8B of new business and renewals signed in 2025, Investment-grade credit profile with target ≤3.0x net leverage, EUR 674M unrestricted cash plus EUR 401M restricted at end-2025, World's largest combined GEO/MEO fleet (~120 satellites) post-Intelsat, Growing government revenue pillar (IRIS², GovSat-2, U.S. PTS-G), Dividend maintained (EUR 0.50 per A-share for 2025), Adjusted EBITDA grew to EUR 1,196M in 2025

Risk factors: Net leverage jumped from 1.1x to 3.9x post-Intelsat acquisition, Equity attributable to parent dropped 23% in 2025, Reported net loss of EUR 95M in 2025, History of large asset writedowns (EUR 3.7B impairment in 2023, EUR 123M in 2024, EUR 146M in 2025), Structural decline in Media/Video revenue, Competitive pressure from LEO constellations (Starlink, Kuiper), Heavy CapEx cycle continues (~EUR 700M guided for 2026), Execution risk on Intelsat integration and synergy delivery, EUR 749M contingent value rights liability (Intelsat-related), EUR 58M FX loss in 2025; EUR/USD volatility risk, Cash dropped from EUR 3,521M to EUR 1,075M in one year

Revenue by product/service

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report