Siemens AG

Germany · owned by Independent (Germany) · www.siemens.com · 55 vendors

Siemens AG is a global technology leader that combines the real and digital worlds to drive innovation across industry, infrastructure, and mobility. The company focuses on industrial AI, automation, electrification, and digital transformation to help customers become more competitive, resilient, and sustainable. Operating in over 200 countries, Siemens delivers solutions spanning smart factories, sustainable cities, and intelligent transport systems.

Resilience scores

Technology vendors

Services catalogue

40 services in catalogue across 6 categories; runs on 55 sub-vendors.

Insights

Last updated 2026-08-11 · revision 12

55 direct vendors, 363 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Siemens AG exhibits a strong foundation for digital migration, driven by its strategic embrace of cloud-native technologies and a clear shift towards SaaS and platform-based offerings. Products like Siemens Xcelerator, NX X, Solid Edge X, Building X, Electrification X, and Gridscale X are explicitly described as cloud-based, SaaS, or open digital platforms, indicating a strategic commitment to cloud migration for its product portfolio. The internal tech stack, rich with Kubernetes, Docker, multiple hyperscaler usage (Azure, AWS, GCP), and CI/CD pipelines (Jenkins, GitLab CI/CD, GitHub Actions), demonstrates significant investment in modern, agile development and deployment practices. Siemens also has a well-defined approach to data residency, leveraging EU-region cloud deployments and established legal mechanisms like Binding Corporate Rules (BCRs) for international data transfers, which is crucial for navigating complex global data sovereignty requirements. The company's strong financial position (€75.9B revenue in 2024) provides the necessary capital to fund large-scale migration initiatives. The vendor relationships data, with 'Total Services: 70' from '14 unique countries', suggests a degree of vendor diversity that could mitigate some lock-in risks, despite the 'Total Vendors: 0' inconsistency. However, migration readiness is significantly challenged by the inherent complexity of Siemens' legacy industrial business. The presence of core products like SIMATIC (PLCs & Industrial Controllers), SINUMERIK (CNC Systems), and TIA Portal (flagship industrial automation engineering framework) implies a substantial number of legacy, on-premise industrial control systems that are difficult and costly to modernize or migrate to the cloud. The 'Assessment Required' and 'High Risk' statuses for the EU AI Act, EU Cyber Resilience Act, and EU Data Act introduce substantial compliance hurdles, necessitating rigorous conformity assessments, cybersecurity by design, and new data access/portability mechanisms for connected products and AI systems, adding significant overhead to any migration strategy. Furthermore, the intricate web of global data residency requirements, including specific localization laws in Germany, China, India, and for US government contracts, demands meticulous architectural planning to ensure compliance during and after migration. The 'Unknown' vendor lock-in risk also represents a potential impediment, as critical legacy systems might be tied to specific vendors or technologies, complicating their transition. Overall, while Siemens has the technical capabilities and strategic intent for migration, the scale of its legacy footprint and the demanding regulatory environment present considerable challenges that temper its overall readiness.

Compliance

17 in-scope frameworks identified; showing 3.

CPRA — Assessment Required

Siemens AG has significant US operations and serves California-based consumers and businesses through its digital platforms and products. Risk is Medium because: (1) Siemens' cloud platforms (Xcelerator, Building X, etc.) likely serve California-based businesses and their employees; (2) CCPA/CPRA applies to businesses with annual gross revenues over $25M (Siemens far exceeds this), buying/selling/sharing personal information of 100,000+ California consumers, or deriving 50%+ of revenue from selling personal information; (3) Siemens' US operations (Siemens Corporation, Siemens Industry Inc.) are directly subject to CCPA/CPRA; (4) Penalties: $2,500 per unintentional violation, $7,500 per intentional violation. Risk is moderated by Siemens' GDPR compliance infrastructure, which provides a strong foundation for CCPA/CPRA compliance.

Evidence: https://www.siemens.com/us/en/general/privacy-notice.html, https://cppa.ca.gov/regulations/, https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.100, https://www.siemens.com/global/en/general/privacy-notice.html

ISAE 3000 (source) — Compliant

Siemens AG is a publicly listed company on the Frankfurt Stock Exchange (DAX 40) and is subject to extensive external assurance requirements. Risk is Low because: (1) Siemens' Sustainability Report (non-financial reporting) is subject to ISAE 3000 limited assurance by external auditors (Ernst & Young GmbH Wirtschaftsprüfungsgesellschaft); (2) This is a well-established practice for DAX 40 companies; (3) Siemens has a mature sustainability reporting infrastructure aligned with GRI Standards, TCFD, and EU CSRD requirements; (4) The assurance engagement is conducted annually by a Big Four firm with deep familiarity with Siemens' operations. The primary risk is the transition from limited to reasonable assurance under EU CSRD requirements.

Evidence: https://www.siemens.com/global/en/company/sustainability/reporting-and-guidelines.html, https://assets.new.siemens.com/siemens/assets/api/uuid:annual-report-2023/siemens-annual-report-2023.pdf, https://www.ifac.org/system/files/publications/files/ISAE-3000-Revised.pdf, https://www.siemens.com/global/en/company/investor-relations/financial-publications.html

GDPR (source) — Compliant

Siemens AG is headquartered in Munich, Germany — an EU member state — making GDPR unconditionally applicable. As a company with ~320,000 employees globally and millions of customers, suppliers, and partners, Siemens processes vast quantities of personal data across HR, sales, procurement, and digital services (e.g., Siemens Xcelerator cloud platform). The risk level is Medium rather than Low because: (1) the sheer scale and complexity of cross-border data flows across 190+ countries creates ongoing compliance complexity; (2) Siemens operates cloud-based SaaS platforms (Building X, Electrification X, NX X) that process customer personal data; (3) enforcement by German DPAs (particularly the Bavarian State Office for Data Protection Supervision, BayLDA) is active and rigorous; (4) GDPR fines can reach €20M or 4% of global annual turnover (~€3B for Siemens). However, Siemens has a well-documented compliance infrastructure, a designated Group Data Protection Officer, and published privacy policies, reducing the likelihood of systemic non-compliance.

Evidence: https://www.siemens.com/global/en/general/privacy-notice.html, https://www.siemens.com/global/en/company/sustainability/compliance.html, https://assets.new.siemens.com/siemens/assets/api/uuid:c9e3d5e5-7e3e-4e3e-8e3e-7e3e4e3e8e3e/siemens-annual-report-2023.pdf, https://www.siemens.com/global/en/company/sustainability/reporting-and-guidelines/data-privacy.html, https://gdpr-info.eu/art-37-gdpr/

Financials

Three-year financials

Financial Resilience Score: 9/10

Siemens AG demonstrates very high financial resilience, underpinned by its scale (~€79 bn revenue), broad diversification across four industrial segments (Digital Industries, Smart Infrastructure, Mobility, Siemens Healthineers) plus financial services, and consistently strong cash generation of €10.8 bn free cash flow in FY2025—well above net income of €10.4 bn. Industrial Business profit margins have held steady at ~15.4%, and the book-to-bill ratio remains above 1 (orders of €88.4 bn vs revenue of €78.9 bn), providing multi-year revenue visibility especially in Mobility's large rail contracts. The company maintains an investment-grade credit profile (historically A/A+ from S&P and Moody's), giving low-cost access to capital markets. Its R&D intensity (~8.4% of revenue, €6.6 bn) and industrial software leadership (top-10 global software company) support durable competitive advantages, while the 67% stake in listed Siemens Healthineers provides a valuable and liquid strategic asset. Portfolio streamlining since 2018–2020 (Healthineers IPO, Siemens Energy spin-off) has focused the group on higher-margin industrial technology and healthcare. Key risks include cyclical exposure in Digital Industries (short-cycle automation, weak China demand in FY2024–2025), lower Mobility margins (8.8%) with fixed-price contract execution risk, geopolitical and trade tensions (33% Americas exposure, 21% Asia), FX translation risk given only 15% of sales in Germany, and integration risks from the Altair acquisition and ONE Tech Company reorganization.

Key strengths: Scale and diversification across four industrial segments plus financial services, Strong free cash flow of €10.8B in FY2025, exceeding net income, Robust order book with book-to-bill above 1 (€88.4B orders vs €78.9B revenue), High R&D intensity of ~8.4% of revenue (€6.6B, 53,200 R&D employees), Investment-grade credit profile (A/A+), Digital revenue growing 14% CAGR FY20–24, reaching ~€9B, 67% stake in listed Siemens Healthineers provides strategic asset, Industrial Business margin steady at ~15.4%

Risk factors: Cyclical exposure in Digital Industries (short-cycle automation), China market weakness affecting Digital Industries, Low Mobility margin (8.8%) with fixed-price rail contract execution risk, Geopolitical and trade tensions (US tariffs, China slowdown), FX translation risk (only 15% of sales in Germany), Integration risk from Altair acquisition and ONE Tech Company reorganization, Legacy pension and long-term project liabilities, Portfolio complexity

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report