SITA

Switzerland · owned by Independent (Switzerland) · www.sita.aero · 4 vendors

SITA is the world's leading specialist in air transport communications and information technology, providing IT solutions to airlines, airports, aircraft, and governments. Its technology underpins critical operations including passenger processing, baggage management, border management, and air traffic management. SITA is a member-owned cooperative serving virtually every major airline and airport worldwide.

Resilience scores

Disruption prediction

SITA has an estimated 11% probability of disruption in the next 6 months.

3 of SITA's 4 vendors monitored for disruptions.

Technology vendors

Services catalogue

16 services in catalogue across 4 categories; runs on 4 sub-vendors.

Insights

Last updated 2026-07-30 · revision 3

4 direct vendors, 119 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

SITA exhibits high migration readiness, primarily driven by its highly modern and cloud-native technology stack. The extensive use of Microsoft Azure, AWS, Kubernetes, Docker, microservices architecture, and CI/CD pipelines positions SITA favorably for seamless migrations to new environments or further cloud adoption. Their embrace of API-First Integration Architecture also facilitates easier integration and decoupling during migration efforts. Financially, SITA's strong revenue of US$1.7 billion and 18% growth provide ample resources to fund complex migration projects. The regulatory environment, including ICAO standards, IATA initiatives, GDPR, PCI DSS, and NIS2 compliance, presents a complex landscape. However, SITA's existing comprehensive certifications and global data residency management capabilities indicate a mature approach to compliance, which, while adding complexity, also means they possess the expertise and processes to navigate these requirements during migration. The primary challenge and area of uncertainty lie in vendor relationships. The data indicates 5 external services from vendors with headquarters in the United States and Denmark, and the 'Vendor Lock-in Risk' is explicitly stated as 'Unknown'. This lack of clarity on vendor lock-in could pose a significant hurdle if these services are deeply embedded or have restrictive contracts. However, the number of external services (5) is not excessively high, suggesting that potential lock-in might be manageable. The geographic concentration of vendors in two countries is also a minor consideration for migration complexity.

Compliance

10 in-scope frameworks identified; showing 3.

EU AI Act (source) — Assessment Required

Risk is rated High because: (1) SITA deploys biometric identification systems at airports (facial recognition for passenger processing and border management) — these are classified as 'high-risk AI systems' under EU AI Act Annex III; (2) SITA's border management solutions for EU governments involve real-time biometric verification, which may trigger 'prohibited' or 'high-risk' AI system classifications; (3) SITA's AI-powered disruption management, predictive analytics, and automated passenger processing systems may also qualify as high-risk AI; (4) the EU AI Act's high-risk provisions are phasing in from August 2026, creating immediate compliance urgency; (5) penalties for non-compliance with prohibited AI practices reach €35M or 7% of global turnover.

Evidence: https://www.sita.aero/about-us/pressroom/news-releases/hamad-international-airport-rolls-out-biometric-travel-across-more-than-700-touchpoints-one-of-the-largest-rollouts-of-its-kind-globally/, https://www.sita.aero/solutions/sita-at-borders/trusted-identity/sita-digital-travel-id/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689

DORA (source) — Assessment Required

Risk is rated Medium because: (1) DORA applies to financial entities and their critical ICT third-party service providers in the EU; (2) SITA provides IT services to airlines and airports, some of which may be classified as financial entities or operate financial services (e.g., airline payment processing, airport retail); (3) SITA's CHAMP Cargosystems subsidiary serves the air cargo supply chain, which intersects with financial services; (4) if SITA is designated as a 'critical ICT third-party service provider' under DORA, it would be subject to direct EU oversight; (5) DORA has been in force since January 17, 2025. Risk is Medium rather than High because SITA's primary customers (airlines, airports) are not typically classified as financial entities under DORA, reducing the likelihood of SITA being designated as a critical ICT provider under DORA's specific scope.

Evidence: https://www.sita.aero/about-us/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554

SOC 2 (source) — Assessment Required

SOC 2 risk is rated Medium because: (1) SITA is a major cloud and managed IT services provider to 2,500+ airlines, airports, and government customers — exactly the profile for which SOC 2 Type II reports are standard market expectations; (2) SITA's customers (major airlines, airports, governments) routinely require SOC 2 reports as part of vendor due diligence; (3) absence of a publicly available SOC 2 report could indicate either that reports exist but are not publicly disclosed (common practice — SOC 2 reports are typically shared under NDA with customers) or that SITA has not obtained SOC 2 certification; (4) the 2021 data breach increases the importance of demonstrable third-party security assurance. Risk is Medium rather than High because SOC 2 is a voluntary framework (not legally mandated), and SITA may satisfy customer requirements through alternative certifications (e.g., ISO 27001) or contractual security TOMs.

Evidence: https://www.sita.aero/legal/sita-privacy-resource-center/security-toms/, https://www.sita.aero/legal/privacy-at-sita/, https://www.sita.aero/about-us/services-excellence/

Financials

Three-year financials

Financial Resilience Score: 7/10

SITA demonstrates strong financial resilience underpinned by its unique member-owned cooperative structure, in which ~400+ airlines, airports, and aviation stakeholders are simultaneously owners and customers. This alignment produces exceptionally sticky, multi-year recurring revenues from mission-critical IT services (messaging, baggage tracing via WorldTracer, passenger processing, border management), with switching costs that are structurally high due to deep integration with airport and airline core systems. The company has delivered four consecutive years of 7-8% revenue growth, fully recovering to its pre-pandemic peak of US$1.71 billion in 2025, and continues to invest US$93M (~5.4% of revenue) in R&D to sustain differentiation in AI, biometrics, and digital identity. However, the resilience assessment is tempered by material transparency limitations: SITA does not publicly disclose EBIT, net income, or shareholders' equity, making external credit assessment difficult. The business is also highly cyclical, with ~100% exposure to air transport — the 2020-2021 pandemic caused a sharp revenue decline (~20%) and workforce reductions, illustrating vulnerability to industry-wide shocks. Competition is intensifying from Amadeus, Sabre, IBS Software, NEC, Idemia, Thales, and cloud hyperscalers, while FX volatility (USD reporting vs. EUR/GBP/INR/CHF cost base) adds margin pressure. Overall, the cooperative model and dominant market positions justify a solid but not top-tier resilience score.

Key strengths: Member-owned cooperative model aligns ~400+ airline/airport owners as customers, ensuring low churn, Four consecutive years of 7-8% revenue growth (2022-2025), reaching pre-pandemic peak of US$1.71B, Near-monopoly positions in baggage tracing (WorldTracer) and industry messaging, Serves ~2,500 customers across 200+ countries, covering 95% of international destinations, Recurring/subscription revenue mix from multi-year managed services provides predictable cash flow, US$93M R&D investment (~5.4% of revenue) supports AI, biometrics, and digital identity differentiation, Active inorganic growth: CCM Group acquisition (2025) and Big Blue Analytics (2026)

Risk factors: 100% revenue exposure to cyclical air transport industry (demonstrated by ~20% revenue drop in 2020-2021), Opaque financials: EBIT, net income, and shareholders' equity not publicly disclosed, Intensifying competition from Amadeus, Sabre, IBS Software, NEC, Idemia, Thales, and cloud hyperscalers, Geopolitical/regulatory exposure via border-management and biometric government contracts, FX volatility: USD reporting with significant EUR, GBP, INR, CHF cost base, Customer concentration by industry (all air-transport related)

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report