[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
ACQUISITION

The vendor is acquired. The contract you signed no longer exists

In November 2023, Broadcom completed its $61 billion acquisition of VMware. The following year, AT&T said it received a proposed annual increase of 1,050% for VMware support. Enterprises were forced to reassess a deeply embedded dependency on the acquirer's terms.

What happened

VMware's virtualisation platform underpins infrastructure across banking, telecommunications, government and healthcare. Broadcom's acquisition gave it control of the product, licensing terms, support arrangements and renewal timelines.

Perpetual licences were discontinued in favour of subscription bundles. Customers that had relied on long-term support found themselves evaluating new commercial terms and difficult migration programmes.

AT&T became the most visible public example. In legal filings it said a proposed annual increase of 1,050% was extreme, while estimating that moving away from VMware could cost $40–50 million and take years because the software was embedded across thousands of servers.

Incident at a glance

Acquisition value
$61B
AT&T proposed annual increase
+1,050%
AT&T virtual machines
75,000
AT&T servers
~8,600
Estimated AT&T migration cost
$40–50M
Migration complexity
Years of engineering work

The root cause

Every enterprise facing a renewal shock had implicitly accepted an unverified dependency: the assumption that the vendor would continue operating on affordable terms. Acquisition can eliminate that assumption quickly.

Software escrow addresses custody. Custody alone does not answer the harder question: can the enterprise operate the software without the vendor if it has to? That answer requires verified recoverability before a negotiation, not during one.

What would Proof of Recovery have changed?

  • An enterprise with current signed Proof of Recovery enters a renewal negotiation from a stronger position because it can demonstrate a tested independent operating path.
  • Migration planning begins from a verified baseline rather than an unknown software state.
  • The board and risk committee have evidence of recoverability on file before the acquisition event, not a scramble after it.

When the acquirer controls the licence, the SLA and the support team, the negotiating position that matters is whether you can operate without them

The regulatory consequence

Acquisition and concentration risk are addressed through exit-planning requirements under EU DORA, the UK FCA's operational-resilience framework and India's RBI IT Directions. Each expects institutions to demonstrate that they can exit critical outsourced dependencies in an orderly way.

Which of your critical vendors could be acquired tomorrow?

Book a briefing