Spirent Communications
UK · www.spirent.com · 12 vendors
Resilience scores
- Digital Sovereignty: 100
- Digital Resilience: 7
- Financial Resilience: 7
Technology vendors
- Adobe Inc. — Technology — United States
- Broadcom Inc. — Technology — United States
- Google LLC — Technology — United States
- and 9 more
Services catalogue
5 services in catalogue across 3 categories; runs on 12 sub-vendors.
- Personal Data Processing
- Avalanche
- Maritime AIS
Insights
Last updated 2026-08-02 · revision 1
12 direct vendors, 199 subvendors
Direct vendors by controlling owner country (sample)
- United States: 12
Subvendors by controlling owner country (sample)
- Czech Republic: 1
- United Kingdom: 3
- Belgium: 3
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Spirent's migration readiness is significantly bolstered by its modern internal tech stack, which includes Docker, Kubernetes, AWS, and Microsoft Azure. This foundation indicates a strong capability for cloud-native adoption, containerization, and potentially microservices architectures, facilitating easier migration to cloud environments. The absence of specified data residency requirements could also simplify migration planning by reducing complex compliance hurdles. However, a notable challenge arises from the vendor relationships. The data is contradictory, showing 'Total Vendors: 0' but also 'Total Services: 12' and 'Vendor HQ Countries: United States'. Interpreting this as actual vendor relationships, the concentration of all vendors in the United States for 12 services suggests a potential for significant vendor lock-in. This lack of vendor diversity and geographic concentration could complicate and increase the cost of migration efforts, as disentangling from these dependencies might be challenging. Information regarding the regulatory environment and financial stability (ability to fund migration) is not available, which limits a complete assessment of migration challenges and opportunities.
Compliance
8 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
ISO 27001 is highly relevant for Spirent given its cybersecurity services (SecurityLabs), network testing solutions, and handling of sensitive customer network configurations and test data. Risk is Medium because: (1) Spirent's enterprise customers in telecom, defense, and financial services sectors routinely require ISO 27001 certification from technology vendors; (2) Spirent's SecurityLabs cybersecurity assessment services involve access to customer security environments; (3) as part of Keysight Technologies, ISO 27001 certification may be pursued at the parent company level. The risk is not High because Spirent is a tooling/testing vendor rather than a data processor of highly sensitive personal data.
Evidence: https://www.spirent.com, https://www.spirent.com/products/securitylabs-cybersecurity-services
FCC Regulations — Assessment Required
Spirent provides testing equipment and services to US telecommunications carriers but is not itself a telecommunications carrier subject to FCC common carrier regulations. Risk is Low because Spirent is a vendor/supplier to telecom companies rather than a regulated entity. However, some of Spirent's RF testing equipment may require FCC equipment authorization (Part 15, Part 18), and its positioning/GNSS simulation equipment may have FCC implications.
Evidence: https://www.spirent.com, https://www.fcc.gov/engineering-technology/laboratory-division/general/equipment-authorization
NIS2 (source) — Assessment Required
NIS2 (EU Directive 2022/2555, transposed by October 2024) may apply to Spirent in its capacity as a digital infrastructure or ICT service management provider operating in the EU. Spirent provides network testing, cybersecurity assessment, and assurance solutions to telecom operators, cloud providers, and critical infrastructure operators across the EU. Under NIS2, 'ICT service management' and 'digital providers' (including managed security testing services) may qualify as Important Entities. Risk is Medium because: (1) Spirent's EU operations likely exceed the 50-employee/€10M turnover thresholds for Important Entities; (2) Spirent's cybersecurity services (SecurityLabs) and network testing tools are used by entities in NIS2-regulated sectors; (3) however, Spirent is primarily a B2B testing/tooling vendor rather than a direct operator of critical infrastructure, which may reduce direct NIS2 applicability. A formal legal assessment by EU counsel is required to determine entity classification.
Evidence: https://www.spirent.com, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555
Financials
Three-year financials
- 2023: revenue $474.7M, EBIT $60.6M, equity $320M
- 2022: revenue $607.5M, EBIT $133.7M, equity $355M
- 2021: revenue $605.8M, EBIT $118.6M, equity $350M
Financial Resilience Score: 7/10
Spirent Communications demonstrated strong financial resilience through its debt-free balance sheet and persistent net cash position of $140-180M during 2021-2023. The company maintained a high-quality customer base including major telecom operators, network equipment vendors, hyperscalers, and defence/aerospace clients, providing diverse revenue streams. A meaningful share of revenue came from software subscriptions and support services, giving some visibility on future income. However, FY2023 revealed significant vulnerability to cyclical downturns, with revenue falling 21.9% and adjusted operating profit more than halving due to a sharp slowdown in operator 5G capital spending, particularly in North America and China. This demonstrates high sensitivity to CAPEX cycles of a small number of tier-1 telcos and network vendors. Despite this cyclicality, the company's strong IP moat in GNSS/PNT simulation and 5G test, combined with high switching costs, supported a healthy premium takeover by Keysight Technologies at approximately £1.16bn in 2024.
Key strengths: Debt-free balance sheet with persistent net cash position ($140-180M), High-quality customer base including major telecom operators and network vendors, Recurring revenue from software subscriptions and support services, Deep IP moat in GNSS/PNT simulation and 5G test, Consistent dividend track record pre-takeover
Risk factors: High cyclicality tied to CAPEX cycles of small number of tier-1 telcos, Customer concentration with top 10 customers ~40-50% of revenue, Geographic exposure to US and China simultaneously weakened in 2023, US-China tech decoupling and export controls create structural risk, Technology transition risk requiring success in Open RAN, 6G, cybersecurity, 800G Ethernet
Revenue by geography
- Americas: 47%
- Asia Pacific: 31%
- EMEA: 22%
Revenue by product/service
- Networks & Security: 60%
- Connected Devices: 21%
- Lifecycle Service Assurance: 19%
Workforce by country
- United States: 650
- United Kingdom: 400
- Other: 250
- China: 200
- India: 200
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.