WorldStream B.V.
Netherlands · www.worldstream.com · 17 vendors
Resilience scores
- Digital Sovereignty: 18
- Digital Resilience: 9
- Financial Resilience: 7
Technology vendors
- Anthropic, PBC — Technology — United States
- Broadcom Inc. — Technology — United States
- Hewlett Packard Enterprise — Technology — United States
- and 30 more
Services catalogue
4 services in catalogue across 1 category; runs on 17 sub-vendors.
- Infrastructure hosting
- Dedicated Servers / Colocation
- WorldStream Hosting
Insights
Last updated 2026-07-30 · revision 6
17 direct vendors, 228 subvendors
Direct vendors by controlling owner country (sample)
- India: 2
- Netherlands: 1
- United States: 12
Subvendors by controlling owner country (sample)
- China: 2
- Luxembourg: 1
- Germany: 10
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
WorldStream B.V. exhibits medium migration readiness, largely influenced by their strategic positioning and existing infrastructure. Their tech stack is modern, offering flexible cloud, private cloud, bare metal compute, and various storage services, built on virtualization platforms like VMware and Proxmox VE. This indicates a capability to manage and offer diverse infrastructure. However, their core business model is to *be* the sovereign cloud and bare metal infrastructure provider, focusing on 'cloud repatriation' rather than migrating their own core services to external hyperscalers. This inherent strategic direction and significant investment in their own data centers and network fabric (Nokia, Arista) creates a form of 'lock-in' to their current operational paradigm. Migrating their entire infrastructure to a fundamentally different platform (e.g., a public cloud hyperscaler) would be a massive undertaking, potentially undermining their value proposition of EU data sovereignty and control. While they utilize multiple vendors for hardware and software (Arista, VMware, Nokia, Fortinet, HPE, Dell, AMD), reliance on specific virtualization platforms like VMware could present challenges for a complete re-platforming. Their extensive regulatory compliance and strict data residency requirements (all operations in the Netherlands, satisfying GDPR and EU digital sovereignty) are strengths for their customers but would add complexity and limit options if WorldStream itself were to migrate to a non-EU or less controlled environment. The 'Total Vendors: 0' in the vendor relationships section is contradictory to the listed internal tech stack, but assuming the tech stack vendors are accurate, they have a moderate number of core vendors. The 'Vendor Geographic Diversity' across 6 countries is a positive for supplier resilience, but doesn't directly translate to ease of migrating their own core infrastructure. Overall, while their technology is modern, their business model and deep integration into their own physical infrastructure make a fundamental migration of their core services a complex and potentially undesirable proposition.
Compliance
9 in-scope frameworks identified; showing 3.
ISO 14001 — Compliant
WorldStream holds a current ISO 14001:2022/Amd.1:2024 certification (latest audit: 20-01-2024) for environmental management. As a data center operator, environmental management is relevant given energy consumption. They also use 100% renewable energy. Risk is Low given the current, valid certification.
Evidence: https://www.worldstream.com/en/certifications/, https://www.worldstream.com/media/uploads/2025/09/WS-Holding-14001-EN.pdf, https://www.whtop.com/review/worldstream.com
PCI DSS (source) — Compliant
WorldStream holds a current PCI DSS 4.0.1:2024 certification (latest audit: 21-03-2026, valid until 20-03-2027). As an IaaS provider serving fintech and e-commerce clients, PCI DSS compliance for their physical infrastructure is directly relevant. They explicitly state they do not store or process cardholder data themselves, but their certified infrastructure supports clients' PCI DSS obligations. Risk is Low given the current, valid certification.
Evidence: https://www.worldstream.com/en/certifications/, https://www.worldstream.com/media/uploads/2026/03/Noordbeek-PCI-DSS-4.0.1-certificate-WSHolding-B.V.-21032026-20032027.pdf, https://www.worldstream.com/en/international-hosting-provider-worldstream-achieves-pci-dss-certification/, https://hostingjournalist.com/news/international-hosting-company-worldstream-achieves-pci-dss-certification
NEN 7510 — Compliant
WorldStream holds a current NEN 7510:2017+A1:2020 certification (latest audit: 25-07-2025) for healthcare information security. As a provider serving healthcare sector clients in the Netherlands, NEN 7510 is the applicable Dutch standard for healthcare information security. Risk is Low given the current, valid certification.
Evidence: https://www.worldstream.com/en/certifications/, https://www.worldstream.com/media/uploads/2025/09/NBC-NEN-7510-2017-certificaat-WS-Holding-B.V.-2025-2026-NBC039-1-NL-v100-1.pdf
Financials
Three-year financials
- 2023:
- 2022:
- 2021:
Financial Resilience Score: 7/10
Worldstream B.V. is a long-established, privately held Dutch cloud infrastructure provider with material physical assets including multiple owned data centers in the Netherlands. The company has operated since 2006 and grown organically to manage 15,000+ active dedicated servers with 10+ Tbit/s network capacity, indicating sustained cash generation and operational resilience in a capital-intensive industry. Its recurring B2B revenue model with monthly server contracts, colocation, and cloud subscriptions provides high revenue visibility and predictable cash flows. The company benefits from a diversified customer base across financial services, e-commerce, gaming, media, MSPs, SaaS, and security sectors, reducing single-sector concentration risk. Its sovereignty positioning with EU-only staff and data residency provides a competitive tailwind given GDPR, NIS2, and growing European demand for non-US cloud alternatives. Recent partnerships such as Cubbit for sovereign S3 storage suggest active product expansion without heavy capex burden. However, no audited revenue, EBIT, or equity figures are publicly available through company channels or freely available regulatory sources due to Dutch SME disclosure exemptions. Risks include capital intensity requiring ongoing capex, energy cost exposure (with an announced price adjustment effective May 1, 2026), component cost inflation (DDR5 memory prices reportedly up ~307%), and competition from hyperscalers (AWS, Azure, GCP) and larger European peers like OVHcloud, Hetzner, and Leaseweb. The company has no public credit rating and customer concentration is unknown.
Key strengths: Owns multiple data centers in the Netherlands reducing third-party dependency, Long operating history since 2006 with organic growth to 15,000+ servers, Diversified customer base across multiple sectors, Recurring B2B revenue model with monthly subscriptions, EU data sovereignty positioning aligned with GDPR/NIS2 tailwinds, Active product expansion via partnerships (e.g., Cubbit sovereign S3 storage), 10+ Tbit/s network capacity with 24/7 in-house support
Risk factors: High capital intensity requiring ongoing capex for data centers and network equipment, Energy cost exposure with announced price adjustment effective May 1, 2026, Component cost inflation (DDR5 memory prices up ~307%), Competition from hyperscalers (AWS, Azure, GCP) and larger European peers (OVHcloud, Hetzner, Leaseweb), Unknown customer concentration, No public credit rating, Financial opacity due to Dutch SME disclosure exemptions
Revenue by geography
- Netherlands/Europe: 70%
- International: 30%
Revenue by product/service
- Dedicated Servers: 50%
- Colocation: 15%
- Cloud Compute: 15%
- Cloud Storage: 10%
- Network Services: 10%
Workforce by country
- Netherlands: 125
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.