Vertex, Inc.
United States · www.vertexinc.com · 30 vendors
Resilience scores
- Digital Sovereignty: 63
- Digital Resilience: 8
- Financial Resilience: 7
Technology vendors
- Adobe Inc. — Technology — United States
- Cookiebot (Cybot A/S) — Technology — Denmark
- Demandware — Technology — United States
- and 27 more
Services catalogue
3 services in catalogue across 2 categories; runs on 30 sub-vendors.
- Applicable Cloud Products
- Cloud Indirect Tax
- O Series
Insights
Last updated 2026-09-13 · revision 1
30 direct vendors, 312 subvendors
Direct vendors by controlling owner country (sample)
- Sweden: 1
- United States: 19
- Germany: 3
Subvendors by controlling owner country (sample)
- Sweden: 12
- Greece: 1
- China: 10
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Vertex, Inc. exhibits high migration readiness, largely driven by its extensive adoption of a multi-cloud strategy across Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI). This indicates significant in-house expertise and experience with cloud environments, which is a critical enabler for future migrations. The use of REST APIs in its internal tech stack suggests a modular and API-driven architecture, which typically facilitates easier and more efficient migration of services and applications. The presence of Drupal 10 also points to a modern content management system. However, several factors introduce uncertainty. A major gap is the absence of financial stability data (revenue concentration, growth history), making it impossible to assess the company's financial capacity to fund large-scale migration projects. The regulatory environment and specific data residency requirements are not specified, which could introduce significant complexities, compliance hurdles, and costs during migration if strict rules apply. The vendor relationship data is contradictory, stating 'Total Vendors: 0' while simultaneously listing 'Total Services: 33' and vendor geographic diversity. If 'Total Vendors: 0' is taken literally, it implies minimal external vendor lock-in, which would be a substantial advantage for migration flexibility. If the other vendor data implies existing relationships, the 'Vendor Lock-in Risk' is unknown, though the geographic diversity of these implied vendors (5 countries) suggests a potentially less concentrated vendor landscape. Overall, the strong existing cloud presence is the dominant factor for high readiness, despite the data gaps.
Compliance
9 in-scope frameworks identified; showing 3.
DORA (source) — Assessment Required
DORA (EU Regulation 2022/2554) applies to financial entities in the EU and their critical ICT third-party service providers. DORA became applicable January 17, 2025. Vertex provides tax technology services to financial institutions (banks, insurance companies, investment firms) operating in the EU. If Vertex is classified as a 'critical ICT third-party service provider' to EU financial entities, it would be subject to direct DORA oversight by EU supervisory authorities. Risk is Medium because: (1) Vertex serves financial sector customers globally; (2) Vertex's tax determination and compliance services are embedded in financial transaction processing; (3) however, whether Vertex meets the 'critical' threshold under DORA requires assessment of its systemic importance to EU financial entities; (4) Vertex's existing SOC 2, ISO 27001, and DR capabilities align with DORA's ICT risk management requirements.
Evidence: https://trust.vertexinc.com/, https://www.vertexinc.com/solutions/tax-type/value-added-tax
GDPR (source) — Compliant
Vertex, Inc. is a US-headquartered company but explicitly operates in the EU/EEA — evidenced by UK, German, Spanish, and Portuguese language portals, a UK phone number (+44 20 3906 7630), EU-based subprocessors (ecosio in UK/Germany/Austria, Global VAT Compliance in Netherlands, Oracle in Germany, AWS in Ireland/Germany), and explicit GDPR compliance badge on their Trust Center. The Privacy Policy explicitly references European data protection law, EU Standard Contractual Clauses (SCCs), and the right to lodge complaints with EU supervisory authorities. Risk is Medium rather than Low because: (1) Vertex processes EU personal data at scale as a SaaS/cloud provider serving global enterprises; (2) cross-border data transfers to the US require ongoing SCC maintenance; (3) as a data processor for enterprise customers, Vertex must maintain robust DPA agreements. Risk is not High because Vertex has publicly demonstrated GDPR compliance infrastructure (badge, DPA willingness, SCCs, subprocessor disclosures).
Evidence: https://trust.vertexinc.com/, https://www.vertexinc.com/vertex-privacy-policy, https://www.vertexinc.com/cookie-policy, https://www.vertexinc.com/en-gb, https://www.vertexinc.com/de-de
NIS2 (source) — Assessment Required
Vertex, Inc. is a US-headquartered company but has confirmed EU operations (UK, Germany, Ireland, Netherlands, Austria presence via subprocessors and language portals). NIS2 Directive (EU 2022/2555) applies to 'digital providers' including providers of managed services and cloud computing services operating in the EU. Vertex Cloud is a SaaS platform providing tax compliance and e-invoicing services to large enterprises across the EU. As a digital service provider/managed service provider with EU operations and enterprise-scale customers, Vertex may qualify as an 'Important Entity' under NIS2's digital infrastructure/ICT service management categories. Risk is Medium because: (1) Vertex's SaaS/cloud nature aligns with NIS2 digital provider categories; (2) EU operations are confirmed; (3) Vertex serves critical business functions (tax compliance, e-invoicing) for large enterprises; (4) however, formal NIS2 classification depends on whether Vertex meets the specific 'managed service provider' or 'cloud computing service provider' definitions under NIS2 Article 3 and Annex I/II, which requires legal assessment. No public NIS2 compliance statement found.
Evidence: https://trust.vertexinc.com/, https://www.vertexinc.com/solutions/platform, https://www.vertexinc.com/solutions/e-invoicing, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555
Financials
Three-year financials
- 2025: revenue USD 748M, EBIT USD 2.33M, equity USD 259M
- 2024: revenue USD 667M, EBIT USD -2.23M, equity USD 179M
- 2023: revenue USD 572M, EBIT USD -17.5M, equity USD 253M
Financial Resilience Score: 7/10
Vertex demonstrates solid financial resilience anchored in a highly recurring, subscription-based revenue model (~85% of revenue) with strong retention metrics (Gross Revenue Retention 94-95%, NRR 105-109%). The company serves a sticky enterprise customer base including Fortune 500 clients like Ford, Microsoft, Walmart, and Siemens, with no customer exceeding 10% of revenue. Consistent double-digit revenue growth every year since its 2020 IPO, combined with $314M in cash and $165.5M in operating cash flow in FY2025, provides ample liquidity to weather downturns. However, GAAP profitability remains thin ($2.3M operating income on $748M revenue in FY2025), heavily burdened by stock-based compensation ($57.8M) and D&A ($96.9M). Free cash flow declined 38.8% in 2025 due to elevated capex, and the company carries $337M in convertible senior notes plus ~$74M in contingent consideration liabilities from recent acquisitions. The April 2026 Value Creation Plan restructuring signals that organic margin expansion has been slower than expected. NRR softening from 109% to 105% year-over-year and decelerating revenue growth (from ~17% to ~12%) suggest maturation pressures. That said, structural tailwinds from global e-invoicing mandates and tax digitization, combined with the fast-growing Cloud segment (+27.9% in 2025), position Vertex well for continued growth. The controlled-company dual-class structure limits minority shareholder governance influence.
Key strengths: Highly recurring subscription revenue (~85% of total), Strong customer retention (GRR 94-95%, NRR 105-109%), Enterprise customer base with no >10% concentration, $314M cash and $165.5M operating cash flow in FY2025, Consistent double-digit revenue growth since 2020 IPO, Cloud segment growing ~28% annually, Structural tailwinds from global e-invoicing mandates, Return to GAAP profitability in 2025
Risk factors: Thin GAAP operating margins ($2.3M on $748M revenue), $337M convertible senior notes outstanding, Free cash flow declined 38.8% YoY in 2025, Heavy stock-based compensation ($57.8M in FY2025), NRR softening from 109% to 105%, Decelerating revenue growth (17% to 12%), Integration and earn-out risk from recent acquisitions (~$74M contingent consideration), Competition from Avalara, Sovos, Thomson Reuters, and native ERP tax modules, Controlled-company dual-class share structure limits minority governance, April 2026 restructuring/Value Creation Plan execution risk, North America / SAP-Oracle ecosystem concentration
Revenue by geography
- United States: 88%
- International (Europe, LatAm, APAC): 12%
Revenue by product/service
- Cloud subscriptions: 47%
- On-premise/hybrid subscriptions: 38%
- Services: 15%
Workforce by country
- United States: 1400
- International (Europe/LatAm): 400
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.